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Novell  raising  security  profile 


■  BY  DENI  CONNOR 

PROVO,  UTAH  —  CEO  Jack 
Messman  wants  Novell  to  be 
known  for  its  security  offerings, 
which  means  a  team  of  develop¬ 
ers  has  been  hired  to  rescue  the 
company’s  dormant  BorderMan- 
ager  product  from  the  scrap  heap 
and  enhance  its  other  authen¬ 
tication  and  access  software. 

While  the  move  has  customers 
applauding,  industry  experts 


question  whether  Novell  can 
compete  head-to-head  with  more 
established  security  leaders. 

The  struggling  network  vendor 
shelved  BorderManager  last  year 
to  the  chagrin  of  users  who  say 
the  Internet  access  and  authenti¬ 
cation  product,  though  miserably 
outdated,  is  one  of  the  best.  Novell 
will  release  a  new  version  of 
BorderManager  in  April  the  com¬ 
pany  says  will  revitalizes  the 
product  —  last  revised  in  1999  — 


and  make  it  a  linchpin  of  the 
company’s  security  suite  that  was 
released  last  month. 

This  bundle,  called  Secure 
Access,  provides  single  sign-on 
capabilities,  user  authorization 
and  authentication  to  applica¬ 
tions,  databases  and  platforms. 
The  bundle  includes  six  other 
products:  SecureLogin,  iChain. 
eDirectory,  Novell  Modular  Auth¬ 
entication  Services  (NMAS),  No- 
See  BorderManager,  page  73 


■  BY  DENISE  PAPPALARDO 


WorldCom  is  juicing  up  its 
voice-over-IP  service  to  offer 
voice  and  data  network  conver¬ 
gence  to  the  desktop,  a  move 
that  could  result  in  significant 
customer  cost  savings. 

The  service  provider  plans  to 
provide  support  for  native  Ses¬ 
sion  Initiation  Protocol  (SIP)  to 
the  desktop  for  its  IP  Com¬ 
munications  service  customers 
next  month.  The  enhancement 
will  let  users  plug  Cisco  or  Ping- 
tel  SIP  desktop  telephones  dir¬ 
ectly  into  their  LANs,  eliminating 
the  need  for  separate  voice  and 
data  networks.  WorldCom  also 
expects  to  extend  the  reach  of 
its  IP  Communications  service 
to  managed  IP  VPN,  dedicated 
See  VoIP,  page  72 


•  VPNs  take  center  stage  at  conference.  Page  14. 

•  Our  reporter's  notebook  looks  beyond  the 
major  announcements.  Page  14. 

•  Visit  www.nwfusion.com  for  a  complete  wrap-up 
of  ComNet  2002.  DocFinder:  7946 
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Joe  Inzerillo, 

CTO  of  Chicago's 
United  Center, 
says  Linux  helps 
professional 
sports  teams  that 
use  the  facility. 


Enterprise  endgame 

■  BY  DENI  CONNOR 

Linux  proponents  say  the  tech¬ 
nology  can  help  large  businesses 
do  just  about  anything  —  even 
aid  professional  athletes  win 
championships. 

At  least  that’s  what  Joe  Inzerillo,  CTO  for  Chicago’s  United  Center, 
hopes.  He  has  installed  a  Linux-based  real-time  video  system  that  the 
coaches  for  the  Bulls  basketball  and  Blackhawks  hockey  teams  use 
to  analyze  the  strengths  and  weaknesses  of  rivals. 

“When  you  look  at  the  resources  and  what  you  are  doing  with  them, 
it’s  clear  that  the  Linux  decisions  we’ve  made  have  let  us  do  a  whole 
lot  more  with  a  whole  lot  less,”  Inzerillo  says. 

In  this,  the  second  of  our  two-part  look  at  Linux  and  open  source 
software  in  corporations,  users  say  Linux  lets  them  deploy  stable,  reli- 

See  Evolution,  page  16 

■  For  more  Linux  news,  see  page  12. 
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No  tolls,  no  dead  ends.  Only  Sun  ONE  software 

puts  your  entire  IT  infrastructure  into  high  gear. 

* 

A  lot  of  companies  are  out  there  trying  to  sell  you  an  "integrated  Web  Services  platform." 
But  what  they're  really  trying  to  do  is  lock  you  into  theirs.  Of  course,  integrating  your 
information  assets  will  allow  you  to  offer  more  services,  get  bigger  savings  and  earn 
greater  profits.  You'll  also  get  better  customer  service,  tighter  supply  chains  and  achieve 
increased  productivity.  But  how  do  you  do  it  without  ripping  out  and  replacing  everything? 
And  how  do  you  make  it  future-proof?  Sun™  ONE  is  the  answer. 


Visit  www.sun.com/sunoneinfo  to  register  to  receive  the  Sun  ONE  starter  kit  and  join  the  online  Sun  ONE  community. 


©2001  Sun  M«josysiems.  Inc  All  rights  res erved  Sun.  Sun  Microsystems,  the  Sun  logo,  the  Sun  CM  toga.  java.  iPlanet.  forte.  Solans,  force  and  SunTone  are  trademarks  or  registered  trademarks  of  Sun  Microsystems,  inc  in  the  United  States  and  other  countries.  UNIX  a  a  registered  trademark  in  the  United 

Stales  and  other  countries,  exdusivetr  kensed  through  X/Open  Company.  Ltd 


IT'S  THE  FUEL-INJECTED  JAVA" 
AND  XML  SOFTWARE  PLATFORM. 

Sun  ONE  is  a  software  platform  of  rock- 
solid  products  that  lets  you  integrate 
whatever  services  you  demand.  And 
you  can  leverage  the  power  of  your 
legacy  systems  to  launch  services  today 
without  locking  you  into  a  dead-end 
solution  tomorrow.  Sun  ONE  includes 
the  iPlanet™  product  portfolio,  with  the 
most  popular  LDAP  directory  server  on 
the  market,  and  Forte,u  for  Java™  tools, 
the  quickest  way  to  write  Java  apps 
anywhere.  And  it's  all  built  with  Java 
and  XML  technologies,  supports  SOAP, 
WSDL  and  UDDI,  and  runs  on  Solaris,™ 
the  #1  UNIX®  operating  environment. 


OPEN  STANDARDS  MEAN 
YOU'RE  IN  THE  DRIVER'S  SEAT. 

Unlike  some  people  out  there,  we  don't 
claim  to  know  everything  that's  down 
the  road  ahead.  We  build  our  products 
to  be  open  and  integratable,  meaning 
they  can  work  with  any  of  the  leading 
software  products  available  today. 
The  Sun  ONE  platform  is  optimally 
engineered  to  work  together,  and  with 
whatever  other  standards-based  prod¬ 
ucts  you  have  in  the  platform. 


WE'RE  A  FULL-SERVICE  STATION. 
SO  COME  ON  BY. 

Our  platform  is  designed  to  be  easily 
implemented  by  Sun's  extensive  team  of 
Enterprise  Service  Professionals,  as  well 
as  by  your  favorite  iForce™  ISV,  systems 
integrator  or  reseller,  and  deployed  reliably 
and  securely  as  a  SunTone™  Certified 
solution.  We  know  how  to  integrate 
network  architecture  better  than  anyone. 
Now,  with  Sun  ONE,  we're  launching 
you  into  a  whole  new  realm  of  services, 
savings  and  greater  profits. 


Not  all  firewalls  are  identical. 

Ours  are  faster  and  more  secure,  for  example. 

Symantec"  firewalls  and  security  appliances  offer  some  of  the  fastest  Web  and  file-transfer  throughput  rates  in  the  industry.  And  all  with  no 
compromise  in  security. 

Our  Symantec  Enterprise  Firewall,"  for  example,  is  up  to  150%  faster  than  our  competitor’s  enterprise  firewall Designed  for  companies  that 
need  the  greatest  flexibility  it  allows  you  to  set  granular  control  policies  that  let  the  right  people  in  and  keep  the  wrong  ones  out. 

Symantec’s  VelociRaptor  firewall/VPN  appliance  offers  similarly  impressive  levels  of  speed  and  control 
in  an  appliance  that's  easy  to  install  and  simple  to  use.  A  plug-and-protect  solution,  it’s  flexible,  scalable 
and  priced  affordably. 

Finally,  Symantec  Firewall/VPN  100  and  200  Security  Appliances  are  easy-to-use  and  easy-to-manage 
appliances  for  your  remote  or  branch  offices.  They  allow  for  quick,  secure  access  to  or  from  the 
Internet,  connecting  all  your  network  devices  with  one  product  Symantec Firewall/VPN  100  and  200 

Symantec  firewalls  and  VPN  technology  are  key  components  of  Symantec  Enterprise  Security.  Combining  world-class  technology,  comprehensive 
services  and  global  emergency  response,  Symantec  Enterprise  Security  helps  businesses  run  securely  and  with  confidence. 

Want  to  make  an  informed  decision  about  your  firewall?  Call  800-745-6054  ext.  1,  promo  code  9GL5. 

For  a  free  Security  Reference  Chart  offering  a  wealth  of  information  about  security  threats,  visit  www.  Symantec.  com/ses8.' 


Symantec  VelociRaptor " 


^  Symantec. 
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The  Good  The  Bad  The  Ugly 


Aprisma  to  leave  Enterasys  nest 

■  Aprisma  Management  Technologies,  the  network  management 
software  arm  of  now-defunct  Cabletron,  will  become  an  indepen¬ 
dent  company  this  month.  For  the  past  year,  Aprisma  has  been 
operating  as  an  independent  arm  of  switchmaker  Enterasys,  which 
itself  was  spun  out  of  Cabletron.  Enterasys  last  week  announced  it 
has  set  Feb.  13  as  the  date  for  distribution  of  Aprisma  common 
stock.  Feb.  5  will  be  the  record  date  for  the  distribution.  Aprisma 
officials  say  the  company’s  independence  will  give  customers 
more  confidence  that  Aprisma  software  will  work  with  hardware 
from  Enterasys  competitors  such  as  Foundry  Networks,  Juniper 
Networks  and  Extreme  Networks. 


Netscape  flags  Navigator  flaw 

■  A  security  flaw  in  Netscape’s  Navigator  Web  browser  can  let  malicious  Web  site 
operators  view  the  information  stored  in  cookies  on  a  users  computer,  according  to 
a  security  note  published  on  Netscape’s  Web  site. The  vulnerability  affects  Navigator 
versions  6  through  6.2,  Version  0.9.6  and  earlier  versions  of  Mozilla,  the  open  source 
version  of  Navigator. The  bug  can  be  exploited  by  causing  users  to  visit  a  Web  address 
inserted  into  HTML  code  on  a  Web  page  or  in  an  HTML-formatted  e-mail.  If  the  user 
were  to  view  the  malicious  Web  site,  cookies  could  be  stolen  off  the  user’s  computer. 
Netscape  urges  users  of  Navigator  6  through  6.2  to  upgrade  to  Version  6.2.1,  which 
does  not  contain  the  flaw.  Mozilla  users  should  upgrade  to  Version  0.9.7. 

Adobe  to  buy  e-forms  vendor  Accelio 

■  Software  maker  Adobe  Systems  has  agreed  to  purchase 
Canadian  electronic-forms  software  and  service  provider 
Accelio  in  an  all-stock  deal  valued  at  $72  million,  the  compa¬ 
nies  announced  Friday  “This  acquisition  quickly  positions 
Adobe  as  a  leader  of  business-process  solutions,  which  is  the 
logical  next  step  in  the  evolution  of  our  ePaper  platform. The 
combined  companies  can  supply  our  customers  with  com¬ 
plete  end-tc>end  e-forms  solutions,” said  Bruce  Chizen.CEO  of 
Adobe.  Accelio,  launched  in  1982,  has  650  employees  and 
7,000  customers  worldwide  in  the  financial  services,  banking, 
manufacturing,  utilities  and  public  service  sectors.  Accelio  has  customers  in  more  than  50 
countries  around  the  world,  including  Microsoft,  Citigroup’s  Citibank,  American  Express 
and  70  ' i  of  the  Fortune  100  companies,  according  to  the  company’s  Web  site. 

Ellison:  Oracle  making  leap  to  Linux 

■  Oracle  is  about  to  replace  three  Unix  servers  that  run  the  bulk  of  its  business  appli¬ 
cations  with  a  cluster  of  Intel  servers  running  Linux, CEO  Larry  Ellison  said  last  week.  He 
also  predicted  the  “inevitable"  demise  of  large  server  systems,  exposing  a  potential  con¬ 
flict  of  interest  with  longtime  ally  Sun.  The  Oracle  chief  made  these  comments  while 
touting  the  benefits  of  Oracles  clustering  technology  to  an  audience  of  financial  ana¬ 
lysts.  Instead  of  upgrading  three  of  its  older  Hewlett-Packard  Unix  servers,  Oracle  will 
move  its  application  server  and  business  software  to  Linux-based  Intel  machines  later 
this  year,  Ellison  said. “We’ll  be  on  Linux  no  later  than  the  summer,  so  we’ll  be  running 
our  whole  business  on  Linux,”  he  said. 


Adobe  CEO  Bruce  Chizen 


IBM  made  it  official  last  week:  Big  Blue  lifer  Sam  Palmisano  will  take 
over  the  CEO  reins  from  Lou  Gerstner  on  March  1.  While  Gerstner  has 
had  his  share  of  success  at  the  company, 
the  time  is  right  for  a  change  and; 

Palmisano  looks  to  be  well-quali¬ 
fied  to  take  over. 

Verizon  co-ceo  ivan 

Seidenberg  said  last  week 
that  broadband  services  have 
come  a  long  way  but  that  the 
industry  is  still  not  doing  a  good 
job  of  making  services  accessible 
to  the  masses.  “Forty  percent  of 
homes  don’t  have  a  broadband 
choice,  and  only  6%  of  small 
businesses  have  broadband 
access,”  he  said.  > 

Bankruptcy 

courts  got  even  more 
packed  last  week,  with  service 
providers  Global  Crossing  and 
McLeodUSA  filing  for 
Chapter  11  protection.  Hey, 
maybe  there  really  is  a 
bandwidth  glut  after  all? 


PHIL  D  ISLE Y 


Microsoft  hires  Gharney  to  head  security 

■  Scott  Charney,  a  partner  at  PricewaterhouseCoopers  in  New  York  and  former  chief 
of  computer  crime  at  the  U.S.  Department  of  Justice,  has  accepted  the  post  of  chief 
security  strategist  at  Microsoft.  Charney  takes  over  the  position  left  vacant  by  Howard 
Schmidt,  who  departed  Jan.  28  to  join  the  Bush  administration’s  infrastructure  secu¬ 
rity  program.  Charney  joins  Microsoft  in  the  wake  of  a  conspicuous  internal  push  by 
company  Chairman  Bill  Gates  to  reemphasize  what  he  calls  “trustworthy  computing.” 

AT&T  Wireless,  A0L  become  ‘buddies' 

■  AT&T  Wireless  Services  customers  now  can  yap  and  trade  instant  messages  over  their 
mobile  phones  thanks  to  an  agreement  between  the  carrier  and  AOLTime  Warner  that 
offers  AOL’s  AIM  instant  messaging  service  to  AT&T  customers  who  have  phones  with 
standard  text  messaging  features.  The  agreement  could  benefit  millions  of  AT&T 
Wireless  and  AOL  customers,  letting  them  chat  and  see  whom  of  their  “buddies”  is 
online.  Although  AIM  is  free, customers  interested  in  using  the  instant-messaging  service 
over  their  AT&T  Wireless  phones  would  have  to  pay  the  carrier’s  text  messaging  fees  of 
10  cents  per  outgoing  message  and  no  monthly  charge,  or  $5  per  month  for  100  outgo¬ 
ing  messages  and  10  cents  per  message  thereafter. 

SEC  sets  up  phony  site  as  warning  to  investors 

■  The  Securities  and  Exchange  Commission  is  creating  a  series  of  Web  sites  appear¬ 
ing  to  offer  fantastic  investment  opportunities, similar  to  those  that  con  artists  create, 
only  to  warn  anyone  foolish  enough  to  consider  investing  of  the  dangers  involved. 
The  SEC  recently  launched  a  Web  site  for  a  fictitious  company  called  McWhortle 
Enterprises  that  introduces  the  “established  and  well-known  manufacturer  of  biolog¬ 
ical  defense  mechanisms”  and  its  new  product,  a  “Bio-Hazard  Alert  Detector”  that 
“emits  an  audible  beep  and  flashes  when  in  the  presence  of  all  known  biohazards." 
Readers  are  invited  to  invest,  with  a  promise  of  gains  of  more  than  400%  in  three 
months  and  are  asked  to  provide  credit  card  details  and  a  Social  Security  number 
“for  identification  purposes.”  Pfeople  who  take  the  bait  and  click  on  a  link  are  led  to 
a  page  warning  them  about  rip-offs  and  urging  them  to  do  their  homework  before 
investing. 


THE  COMPAQ  ADAPTIVE  INFRASTRUCTURE  IS  ABOUT  TO  CHANGE  EVERYTHING. 

Technology  has  automated  just  about  everything  these  days.  But  curiously,  the  corporate  data  center  has  lagged  behind. 

There,  highly  paid  people  still  spend  inordinate  amounts  of  time  doing  things  like  manual  fault  searches  and  fingernail¬ 
ripping  server  management  tasks.  It’s  more  than  ironic.  It's  enormously  counterproductive.  Because  every  initiative  a 
corporation  undertakes — whether  it’s  in  operations,  marketing,  accounts  or  HR — goes  through  the  data  center. 

But  the  new  Compaq  Adaptive  Infrastructure  will  take  your  critical  initiatives  farther  and  faster  than  ever  before.  Its  next- 
generation  ProLiant™  Blade-Line  server  technology  features  innovative  architecture  that  conserves  space  and  resources  by 
multiplying  performance  per  square  foot  of  data  center.  And  its  ProLiant  Essentials  management  software  offers  levels  of 
control  scaled  to  your  needs  so  you  can  rapidly  adapt  to  change,  remotely  deploying  new  technology — and  redeploying 
existing  technology — in  the  time  it  takes  to  click  on  a  mouse. 

It’s  a  technological  advance  with  enormous  implications  for  business.  And  Compaq  Global  Services  can  provide  the  expert, 
responsive  support  to  help  you  make  it  happen.  Find  out  more  by  calling  your  Compaq  Account  Representative  or  reseller;  or 
dial  1-800-AT  COMPAQ,  press  option  5  and  mention  priority  code  SCB,  or  log  on  to  compaq.com/ai 

I  Log  on:  compaq.com/ai 
I  Or  call:  1-800-AT-COMPAQ 


©2002  Compaq  Computer  Corporation.  Compaq,  the  Compaq  logo  and  ProLiant  are  registered  in  the  U.S.  Patent  and  Trademark  Office. 
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Lotus'  Domino  plans  disappoint  customers 

Garnet  technology  yanked  from  Domino  6  to  avoid  competing  with  Java  features  in  WebSphere. 


■  BY  JOHN  FONTANA 

ORLANDO  —  Lotus  last  week 
stunned  customers  by  pulling  a 
key  piece  of  technology  from 
the  forthcoming  release  of  Do¬ 
mino,  igniting  a  backlash  by 
users  who  questioned  the  fu¬ 
ture  of  the  product  as  a  Web- 
based  development  platform. 

After  Lotusphere  attendees  first 
warmed  to  Lotus’  plans  for  Dom¬ 
ino  to  become  a  set  of  collabo¬ 
ration  components  that  run  on 
Java  2  Platform  Enterprise  Edi¬ 
tion  (J2EE),they  were  fed  a  bitter 
pill  when  the  company  pulled 
key  Java  technology,  called  Gar¬ 
net,  from  the  forthcoming  Do¬ 
mino  6  package. 

Garnet,  under  development  for 
more  than  a  year,  supplied  sup¬ 
port  for  Java  Server  Pages  (JSP) 
in  Domino.Support  for  JSRa  sim¬ 
ple  programming  mechanism 
for  displaying  dynamic  content 
on  a  Web  page,  was  to  provide  a 
bridge  into  the  J2EE  develop¬ 
ment  world  without  having  to 
purchase  and  deploy  a  full¬ 
blown  J2EE  server,  such  as  IBM’s 
WebSphere. 

“This  would  have  made  Dom¬ 
ino  even  more  viable  as  an  ‘all- 
in-one  integrated  platform,’  very 
coherent  and  low-cost  com¬ 
pared  to  ‘classic’  J2EE  solutions 
involving  WebSphere  and  DB2 
that  require  many  different  peo¬ 
ple  and  skills,”  says  Pejman 
Parandi,  a  senior  Web  developer 
who  asked  that  his  company 
not  be  identified. 

But  IBM  is  no  longer  interested 
in  an  all-in-one  platform,  Par¬ 
andi  says,  and  it  killed  Garnet  to 
avoid  competing  with  J2EE  sup¬ 
port  in  WebSphere. 

Garnet,  which  is  in  the  current 


Ins  and  outs 

Lotus  has  pulled  some  of 
its  Java  technology  out  of 
the  next  release  of  Domino, 
but  other  features  still 
remain. 


In:  J2EE  support 


V  Bundled  WebSphere  App 
Server  4.x  (developer 
version) 

V  JSP  tag  library 

^  Hardened  Java  APIs 

Web  distributed  authoring 
and  versioning 

Multiple  HTTP  stacks 
(Apache,  IIS,  iPlanet) 

Increased  testing  against 
WebSphere 

s/  Single  sign-on  via 
lightweight  third-party 
authentication  with 
WebSphere  app  server 


Out:  Garnet  J2EE  platform 


X  Embedded  J2EE  server  (the  R5 
servlet  engine  is  retained  for 
backward  compatibility) 

X  JSP  and  servlet  editing  in 
designer 

X  JSPs  in  LotusScript 

beta  versions  of  Domino  6,  isn’t 
scheduled  for  inclusion  in  the 
next  beta  that  ships  this  month. 

IBM  officials  say  they  realized 
Garnet  wasn’t  complete  enough 
to  be  a  pure  standards  technol¬ 
ogy  and  that  it  actually  repre¬ 
sented  a  risk  to  positioning 
Domino  as  a  set  of  collaboration 
components  for  what  Lotus  and 
others  are  calling  “contextual 


VPNs,  RAS,  VoIP,  mobile . . .  if  you’re  managing  remote 
and  mobile  workers,  you  need  to  know  the  right  stuff. 
Net.Worker  gives  you  the  scoop  on  the  products  and 
technologies  for  the  untethered  workforce. 
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collaboration”  (see  The  Scoop, 
this  page)  —  the  ability  to  inte¬ 
grate  collaboration  support  into 
business-process  applications. 

But  Lotus  has  been  testing 
Garnet  for  nearly  a  year,  so  its 
demise  caused  surprise  and  dis¬ 
appointment. 

“When  they  showed  the  JSP 
engine  for  Domino  [Garnet] 
last  year,  1  thought  Domino  is 
the  Web  platform  I  will  go  for¬ 
ward  with,”  says  Doug  Hayden, 
IT  project  manager  for  furniture 
maker  Herman  Miller  in  Zee- 
land,  Mich.  “I’m  on  board  with 
the  other  changes,  but  I  am 
disappointed  they  pulled  the 
JSP  engine.  I  don’t  need  Web¬ 
Sphere.  1  look  at  it  as  another 
platform  that  I  would  have  to 
learn,  so  I  thought  it  was  great 
that  I  had  what  I  needed  in 
Domino.” 

Big  Blue's  strategy 

IBM  is  signaling  clearly  that 
Domino  will  become  a  set  of  col¬ 
laborative  components  for  J2EE 
developers  to  add  to  applications 
that  run  on  IBM’s  WebSphere  ser¬ 
ver  and  IBM’s  Web  services  plat¬ 
form,  which  now  includes  the 
DB2  database  and  Tivoli  Systems 
management  wares. 

“There  is  no  question  that  the 
long-term  IBM  strategy  is  to  use 
Domino  to  sell  more  infrastruc¬ 
ture  components  like  WebSphere, 
DB2  and  Tivoli,”  says  Matt  Cain,  an 
analyst  with  the  Meta  Group.“This 
is  going  to  be  a  tumultuous  time 
for  IBM/Lotus  as  they  rationalize 
what  is  Domino.” 

Some  say  the  tumultuous  times 
have  already  started. 

“It  was  nice  to  see  Lotus  get 
the  Web  standards  for  Web  ap¬ 
plication  development  into  Do¬ 
mino,  but  now  they  are  saying 
forget  it,”  says  Edward  Rabin¬ 
ovich,  associate  director  of 
planning  and  architecture  for 
Ernst  and  Young  in  Cleveland. 
“Domino  now  becomes  a  set  of 
classes  you  call  from  Web¬ 
Sphere.  It  all  means  more 
money,  more  training  and  more 
infrastructure.” 

Some  view  the  elimination  of 
Garnet  as  such  a  blow  to  Domino 
that  one  contributor  to  a  discus¬ 
sion  list  on  the  Notes.Net  Web 
site  suggested  Domino  6  be 
renamed  “Domino  Edsel.”  Others 
suggested  that  Domino  will  be¬ 
come  just  another  mail  server  is 


now  on  a  path  to  irrelevance;  and 
that  they  will  begin  shopping  for 
another  Java  server  platform. 

Lotus  officials  reacted  by 
posting  an  explanation  of  the 
Garnet  decision  and  a  fre¬ 
quently  asked  questions  sec¬ 
tion  titled  “Next  Generation 
Collaboration  Strategy”  after 
the  negative  tone  permeated 
the  Notes.Net  site. 

“Building  parallel  infrastructure 


in  Domino  and  WebSphere  does¬ 
n’t  make  a  lot  of  sense  for  us,” says 
Ed  Brill, senior  manager  for  enter¬ 
prise  messaging  at  Lotus.  He  says 
Lotus  would  have  to  spend  mil¬ 
lions  of  dollars  to  develop  and 
support  a  technology  that  already 
exists  within  IBM. 

Brill  says  using  IBM’s  existing 
work  with  WebSphere  is  the  cor¬ 
rect  way  to  make  Domino  data 
available  to  J2EE  applications.* 


It's  all  about  context 


There  is  an  interesting  concept  swirling  around  collabo¬ 
rative  software  that  Lotus  and  Microsoft  are  doing 
their  best  to  elevate  to  buzzword  status:  “contextual 
collaboration." 

The  idea  is  you  can  take  a  slice  of  a  self-contained  col¬ 
laboration  server —  an  e-mail  in-box,  a  calendar,  a  dis¬ 
cussion  group  or  an  instant  messaging  capability  —  and 
slide  it  into  another  application  without  the  hassles  of 
hard-coding. 

The  benefit  is  users  won't  have  to  leave  familiar  applica¬ 
tions  to  enter  a  separate  collaboration  system.  Fewer  appli¬ 
cations  mean  few  interfaces  and  training  issues. 

Collaboration  features  in  business  applications  mean  effi¬ 
ciencies  gained  through  the  ability  to  question,  converse  and 
negotiate  within  the  context  of  one  application.  It’s  the  hu¬ 
man  element,  or  as  close  to  it  as  you  can  get,  for  electronic 
business. 

For  example,  a  customer  relationship  management  applica¬ 
tion  may  have  incorporated  into  its  interface  a  discussion- 
group  component  so  that  a  customer  representative  could 
create  a  forum  to  log  and  answer  questions. 

With  the  advent  of  Web  services,  which  let  pieces  of  code 
be  wrapped  in  standards-based  interfaces,  Lotus  and 
Microsoft  are  trying  to  deconstruct  servers  into  individual 
single-function  components  that  can  be  blended  into  other 
applications. 

Lotus  announced  its  strategy  around  Java  and  Java  2 
Platform  Enterprise  Edition  last  week,  and  Microsoft  is  busy 
constructing  its  story  around  .Net.  However,  neither  vendor 
has  made  significant  progress. 

Meta  Group  analyst  Matt  Cain  coined  the  term  “contex¬ 
tual  collaboration"  about  two  years  ago.  Cain  says  tradi¬ 
tional  collaboration  suites  and  emerging  collaboration 
models,  such  as  peer-to-peer  and  teamware,  "will  evolve 
as  embedded,  process-specific  components  within  busi¬ 
ness  systems.”  Indeed,  Groove  Networks  is  already  work¬ 
ing  with  Microsoft  to  embed  its  peer-to-peer  software 
into  Office. 

IT  executives  can  be  sure  that  accompanying  this  evolu¬ 
tion  will  be  a  steady  diet  of  vendor-led  testimonials  on  con¬ 
textual  collaboration’s  potential  to  make  the  electronic  busi¬ 
ness  world  a  friendlier  place. 


—  John  Fontana 
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Complete  protection  for  your  entire  enterprise. 


When  it  comes  to  protecting  your  business,  you  need  security  that  can  protect  your 
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enterprise,  but  also  view  and  manage  that  security  either  centrally  or  from  multiple 
delegated  locations.  So  you  can  continue  to  grow  and  maximize  new  opportunities 
while  minimizing  your  risk.  And  that's  security  you  can  feel  secure  about. 
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Hackers,  vendors  put  camouflage  to  use 

Latest  virus  relies  on  trick  URL;  start-up  ForeScout  aims  to  fend  off  viruses,  hackers. 


■  BY  ELLEN  MESSMER 

The  “MyParty”  virus,  masquerad¬ 
ing  as  a  URL  for  an  online  archive 
of  photos,  came  as  a  shock  last 
week  to  many  people  who  didn’t 
realize  that  a  mass-mailer  worm 
could  disguise  itself  as  a  harm¬ 
less-looking  link  in  a  message. 

The  virus,  camouflaged  as 
www.mypartyyahoo.com,  urged 
e-mail  recipients  to  click  on  it  to 
see  photos  of  what  was  said  to  be 
the  sender’s  recent  party  But  the 
URL  was  actually  a  computer 
virus  that  left  a  dangerous  back¬ 
door  Trojan  horse  on  infected 
machines  before  mailing  itself  off 
through  the  Microsoft  Outlook 
directory 

“Not  only  did  it  e-mail  to  every¬ 
one,  and  1  mean  everyone,  in  my 
address  book,  but  my  computer 
crashed  shortly  thereafter"  says 
one  MyParty  victim,  who  prefers 
to  remain  anonymous. 

Antivirus  software  vendors 
quickly  issued  a  signature  update 
to  stop  MyParty  last  week,  noting 
people  are  likely  to  suffer  a  new 
mistrust  of  URLs  in  messages  in 
general. 


■  BY  ELLEN  MESSMER 

SUNNYVALE,  CALIF  —  Enter¬ 
prise  customers  looking  to  fortify 
their  networks  tend  to  buy  lots  of 
security  products  from  lots  of 
vendors  because  of  the  choice  of 
firewalls,  intrusion-detection  sys¬ 
tems  and  syslog  analysis  tools 
available.  One  downside  to  this  is 
that  getting  a  read  on  overall  net¬ 
work  security  can  involve  dealing 
with  a  slew  of  separate  manage¬ 
ment  consoles. 

Start-up  ArcSight  thinks  many 
corporations  would  prefer  to  cen¬ 
tralize  the  information  from  these 
security  devices.  To  that  end, 
ArcSight  last  week  introduced 
ArcSight  1.0,  Java-based  server 
software  that  collects  the  output 
from  about  two  dozen  devices. 

ArcSight  1 .0  consists  of  “Smart- 
Agents"  that  can  be  loaded  di¬ 
rectly  on  security  equipment  to 
collect  the  information  as  well  as 
middleware  software  that  will 
receive  the  information  directly 


“This  mass-mailer  worm  will 
impact  the  credibility  of  all  URLs, 
particularly  for  photo  archives 
such  as  Yahoo  and  Shutterfl/ says 
Chris  Wraight,  technical  director 
at  antivirus  software  vendor 
Sophos.  Several  vendors  recalled 
they  had  seen  a  computer  virus 
disguised  once  before,  the  “Cool- 
side”  virus  of  six  months  ago. 

Fortunately,  it’s  not  only  the 
bad  guys  making  use  of  camou¬ 
flage  and  artifice.  Disguise  and 
misinformation  can  help  de¬ 
fend  networks,  too. Security  ven¬ 
dor  ForeScout  Technologies 
next  week  will  introduce  a 
product  called  ActiveScout  that 
combines  an  intrusion-detec¬ 
tion  system  (IDS)  with  the  capa¬ 
bilities  of  a  “honeypot”  to  ward 
off  hackers  and  worms  such  as 
Nimda  and  Code  Red  that  scan 
for  vulnerabilities. 

The  idea  of  a  network-based 
honeypot  is  to  provide  would-be 
hackers  with  fake  information 
about  a  network  by  means  of  a 
decoy  server  to  confuse  them, 
trace  them  back  or  keep  a  record 
for  prosecution.  The  concept  is 
still  new,  but  a  few  companies, 


over  a  network  and  consolidate  it 
as  alerts,  warnings  and  reports  in 
an  Oracle  database. 

ArcSight  can  collect  security  in¬ 
formation  from  Cisco  routers  and 
NetRanger  IDS  systems,  Check 
Point  Software  firewalls,  SNORT 
intrusion-detection  freeware,  En- 
tercept  behavior-blocking  soft¬ 
ware  and  Tripwire  IDS  products. 

ArcSight  1.0  starts  at  $100,000. 
The  security-management  start¬ 
up  wants  to  compete  against  soft¬ 
ware  vendors  with  “security  man¬ 
agement  umbrellas”  of  their  own, 
such  as  NetForensics,  eSecurity 
and  IBM’s  Tivoli  division. 

Corio  has  adopted  ArcSight  to 
get  a  real-time  security  overview 
of  its  application  service  provider 
network. 

“But  you  have  to  tune  it, and  that 
takes  time,”  says  Mark  Milatovich, 
directory  of  security  at  Corio. The 
adjustments  ArcSight  1.0  requires 
means  it  could  be  a  few  months 
before  Corio  gets  the  full  benefits 
of  the  software,  he  says.  ■ 


such  as  Recourse  Technologies 
with  its  ManTrap  product,  have 
developed  honeypots. 

Now  along  comes  ForeScout, an 
Israeli  firm  with  offices  in  Palo 
Alto,  with  a  slightly  different  twist 
of  its  own  to  fool  hackers. 

ActiveScout,  a  rules-based  IDS, 
sits  outside  the  corporate  fire¬ 
wall  to  identify  potential  threats 
and  block  them,  says  Ayelet 
Steinitz,  product  marketing  man¬ 
ager  for  ForeScout,  which  has 
raised  $14  million  since  its 
inception  in  April  2000.  “It  also 
does  discovery  inside  the  net¬ 
work  and  watches  traffic  going 
back  and  forth,”  Steinitz  says. 

When  an  attacker  scanning  with 
tools  —  or  hybrid  worms  that 
scan  —  seeks  to  gain  information 
about  the  corporate  network,  the 
Linux-based  ActiveScout  device 
will  give  back  false  information. 

“It  creates  a  virtual  IP  address,” 
says  one  ActiveScout  beta-test 
customer,  Barry  Choisser,  network 
manager  at  Risk  Management  So¬ 
lutions, a  Newark,  Calif.,  developer 
of  software  applications  for  the 
insurance  industry 

Steinitz  says  ActiveScout  can 
insert  unique  “tagged”  informa¬ 
tion  into  the  stream  of  traffic 
back  to  an  attacker  scanning  for 
open  ports  or  other  information. 
Sometimes  an  attacker  conducts 
reconnaissance  from  many 
addresses,  most  of  them  fake,  a 
trick  used  to  fool  an  IDS.  If  an 
attacker  returns  to  attempt  a 
break-in,  ActiveScout  would  rec¬ 
ognize  the  real  source  of  the 
attack  with  the  tagged  in¬ 
formation,  Steinitz  says. 

ActiveScout,  which  starts  at 
about  $9,000  with  its  manage¬ 
ment  console,  will  be  on  display 
in  two  weeks  at  the  RSA  Confer¬ 
ence  in  San  Jose. 

Choisser  says  his  network  is  sub¬ 
ject  to  dozens  of  scans  and  at¬ 
tempted  break-ins  each  week.  “I 
see  Nimda  and  people  trying  to 
get  through  [Secure  Shell  (SSH)] 
ports,”  he  says. 

The  SSH  Service  is  used  as  a 
secure  alternative  to  telnet  be¬ 
cause  of  its  encryption  and  au¬ 
thentication  options,  but  older 
versions  of  SSH  are  “plagued 
with  several  vulnerabilities,” 
according  to  a  threat-analysis 
report  released  by  managed 
security  services  firm  Riptech 
last  week. 

Hackers  know  about  weak¬ 
nesses  in  SSH  and  they  probe 


Under  attack 

These  are  the  most 
common  network  attacks 
as  reported  by  300  clients 
of  managed  security 
services  vendor  Riptech. 

1.  Microsoft  Index  Services  ISAPI 
Overflow  Attack  47.8% 

2.  Generic  “rootexe”  request  attack 
25.1% 

3.  Microsoft  IIS  Directory 
Transversal  (Unicode)  Attack 
23.5% 

4.  Microsoft  IIS  Superfluous  Decode 
Attack  17% 

5.  Generic  “emd.exen  request  attack 
16.5% 

6.  Scan  for  27374/tep  (SubSeven) 
5% 

7.  Scan  for  vulnerable  and/or 
misconfigured  FTP  servers  3.8% 

8 .  Scats  for  systems  with  RPG(tcp) 
enabled  2.8% 

9.  Scans  for  SSH  service  1.3% 

10.  Scans  for  LPD  service  1.2% 

Figures  total  more  than  100% 
because  multiple  replies  were 
allowed. 


for  them,  which  is  why  SSH 
made  Riptech’s  list  of  “Top  Ten” 
attacks  (see  graphic). 

The  Riptech  report  found  that 
each  of  its  300  customers  sur¬ 
veyed  suffered  an  average  of  25 
attacks  per  week,  with  39%  of  the 
attacks  appearing  to  be  targeted 
at  the  companies.  The  rest  of  the 
attacks  were  random  scans  to 
search  for  vulnerable  systems  on 
the  Internet. 

“The  problem  is,  when  we  get 
scanned,  we  don’t  know  who  it  is; 
we  just  know  it’s  from  an  lSlf  says 
Mark  Parquette,  assistant  vice 
president  of  information  systems 
at  Charter  Bank  in  Wyandotte, 
Mich.,  whose  Cisco  P1X  firewall 
and  NetRanger  IDS  are  moni¬ 
tored  by  managed  services  pro¬ 
vider  NetSolve. 

Although  Parquette  says  the 
ForeScout  equipment  sounds 
promising,  it’s  an  open  question  ! 
whether  smaller  companies  such  | 
as  Charter  Bank  will  allocate  j 
funds  to  buy  it. 

ForeScout:  www.forescout.com 
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Build  &  Automate: 

•  Fastest  Engine 
•Transparent  On-line  Defrag 

•  Smart  Scheduling 

•  Full  Network  Controls  ' 

•  Push  Installation  _____ 
Full  Compatibility:! 

•Windows  9x  mill! 

•Windows  ME  — I — ~  V1' ' 
•Windows  NT  \1-FSS^S=^^ 
•Windows  2000 
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•Windows  XP  , 
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Automatically  eliminate  disk  fragmentation  and  unleash  full  system  speed 
on  one  desktop  or  across  your  entire  site! 


NEW  DISKEEPER®  7.0  "Set  It  and  Forget  It"®  disk 
defragmenter  for  Windows®  is  so  advanced  it  runs 
itself,  precisely  when  needed.  It's  like  hiring  an  expert  to 
constantly  monitor  your  system's  performance  and  keep  it 
at  peak  levels.  New  Diskeeper  7.0  defragments  drives  so 
thoroughly  and  with  such  blazing  speed,  it  makes  manual 
"built-in"  technology  completely  obsolete. 

In  today's  economic  climate,  it's  just  as  important  to  know 
that  Diskeeper  7.0  can  extend  the  productive  life  of  your 
systems  up  to  three  years,  significantly  reduce  your  TCO 
and  cut  help  desk  calls  in  half.  It's  one  reason  9  out  of  10 
corporations  use  Diskeeper  over  any  other  defragmenter. 

In  fact,  it  costs  money  every  day  your  machines  are 
running  without  Diskeeper.  Follow  the  link  on  this  page 
to  buy  it  now. 

www.nwl.diskeeperxom 
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Focused  Development  ot  System  Management  Tools 


Visit  our  website  at 
www.execsoft.com 

1  -800-829-6468 


Advanced  Features: 


New!  "Push  Install"  eliminates 
the  time  and  cost  of  manual 
installation  with  fast,  two-click 
remote  operation. 

New!  Microsoft®  recommended 
lightning  fast  boot-time  defrag  for  important 
system  files  —  remotely  control  &  schedule  across  site. 
Exclusive:  "Smart  Scheduling"™  monitors  and  maintains 
peak  system  performance  intelligently  and  unobtrusively 
without  requiring  assistance. 


Certified  at  the  highest  level  for 
Windows  XP/2000/NT®  and  fully 
compatible  with  Windows  9X. 
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"Disk  fragmentation  can  cause  performance  problems.  You 
should  consider  running  a  defragmentation  program  on  a 
regular  basis.  "*  —  Microsoft  Windows  NT  Server  Resource  Guide 


©  2001  Executive  Software  International,  Inc.  All  Rights  Reserved.  DISKEEPER,  Executive  Software,  the  Executive  Software  logo,  'Set  It  and  Forget  It”  and  'Smart 
Scheduling'  are  either  registered  trademarks  or  trademarks  of  Executive  Software  International,  Inc.  in  the  United  States  and/or  other  countries.  Microsoft,  Windows  and 
the  flag  logo  are  registered  trademarks  or  trademarks  of  Microsoft  Corporation  in  the  United  States  and/or  other  countries.  AH  other  trademarks  and  brand  names  are  the 
property  of  their  respective  owners,  from  Microsoft  Windows  NT  Server  Guide.  Reproduced  by  permission  of  Microsoft  Press.  AH  Rights  Reserved. 
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Users  to  get  read  on  Palm's  Mure 

Observers  say  pressure  is  on  to  release  next  operating  system. 


■  BY  JOHN  COX 

SAN  FRANCISCO  —  Network 
executives  will  get  a  chance  to 
hear  Palm’s  top  executives  lay  out 
the  company’s  direction  at  this 
week’s  PalmSource  conference. 

It  could  be  a  turning  point  for 
Phlm,  which  is  being  hit  with  sev¬ 
eral  challenges  all  at  once: 

•  It’s  in  the  midst  of  a  reorgani¬ 
zation; 

•  The  new  version  of  its  operat¬ 
ing  system,  rewritten  for  the  pow¬ 
erful  ARM  32-bit  microprocessor, 
is  still  not  out; 

•  The  recently  unveiled  Palm 
i705  wireless  handheld  has  met 
with  mixed  reviews,  judging  from 
comments  in  newsgroups  and  on 
Web  sites; 

•  Competition  is  heating  up,  not 
only  from  archrival  Microsoft  and 
its  FbcketPC  2002  operating  sys¬ 
tem,  but  also  from  Palm’s  li¬ 
censees,  such  as  Handspring  and 
Sony; 

•  The  stock  price  has  dropped 
since  August  from  a  52-week  high 


of  nearly  $29  to  less  than  $5. 

All  these  pressures  will  come 
to  bear  on  newcomer  David 
Nagel,  CEO  of  the  recently 
formed  Palm  OS  subsidiary,  who 
makes  his  first  appearance  this 
week  before  thousands  of  Palm 
developers  and  partners.  The 
audience  will  look  for  evidence 
Palm  still  has  a  vision  of  hand¬ 
held  computing  that  relates  to 
the  needs  of  enterprise  network 
users. 

Observers  expect  Nagel  to  lay 
out  a  clear  roadmap  for  the  tran¬ 
sition  of  the  current  Palm  OS  to  a 
32-bit  chip  architecture  and  detail 
how  Palm  will  address  nagging 
security  issues,  improve  wireless 
connectivity  and  ensure  that  its 
products  work  better  with  corpo¬ 
rate  databases  and  applications. 

One  major  announcement  for 
developers  will  be  the  release  of 
reference  applications  for  the 
Palm  OS.  A  joint  effort  by  Palm, 
Kada  Systems,  Oracle,  Sybase  and 
Hexaware  Technologies,  the  ap¬ 
plications  use  embedded  data¬ 


bases,  and  Kada’s  synchroniza¬ 
tion  software  and  APIs  to  let  de¬ 
velopers  more  quickly  build  cus¬ 
tom  applications  for  line-of-busi- 
ness  functions  such  as  customer 
relationship  management. 

“Palm  used  to  have  the  oppor¬ 
tunity  to  command  the  enterprise 
[market],”  says  Ken  Dulaney  an 
analyst  with  Gartner.  “But  it  lost 
that  through  bad  management.” 
Dulaney  cites  the  spinoff  from 
parent  3Com,  Palm’s  IPO  and  sev¬ 
eral  top-level  turnovers,  all  in  less 
than  five  years,  as  culprits. 

“The  FbcketPC  is  interesting  to 
enterprise  IT  because  it  ties  in 
well  with  Microsoft  software,”  Du¬ 
laney  says.  “What  Palm  has  to  do 
now  is  view  Microsoft  as  less  of 
an  enemy  and,  instead,  build  sys¬ 
tems  that  tie  into  Microsoft  [plat¬ 
forms  already  entrenched  in  the 
enterprise] .” 

“Palm  has  had  an  unwavering 
commitment  to  the  enterprise, 
but  the  focus  has  been  frag¬ 
mented,”  says  Kevin  Burden,  an 
analyst  for  IDC. 


et  s  *© 

address  Cole  Cord  Info 

®  0  © 

Clock  Dot®  Book  Documents 

CD  0  £* 

HotSyrx  Memo  Pod  MultiMail 

&  0  © 

MyPcfm  Notepad  Prefs 


Palm's  1705  handheld  features 
built-in  wireless  support. 

Take  security  for  example.  Fblm 
announced  last  November  that 
RSA  Security’s  highly  regarded 
encryption  software  would  be 
associated  in  some  way  with  “fu¬ 
ture  versions”  of  the  Palm  OS.  But 
Palm  never  spelled  out  what  that 
would  mean.  Today  security  for 


Palm  applications  in  the  enter¬ 
prise  remains  a  matter  a  stitching 
together  an  array  of  products 
and  technologies. 

For  a  range  of  enterprise  ap¬ 
plications,  the  Palm  OS  doesn’t 
have  the  muscle  that’s  needed. 
Multithreading,  which  lets  an 
operating  system  simul¬ 
taneously  handle  an 
array  of  tasks,  will 
finally  be  introduced 
ijmm  with  the  ARM-based 
Palm  OS. 

“Proper  multitasking 
will  allow  a  more  stable  system, 
and  allow  a  new  breadth  of  net¬ 
work/wireless  applications  to 
appear]’  says  Russell  Bulmer,  a 
software  engineer,  and  long-time 
Palm  user,  with  Conigma,  a  wire 
less  services  start-up  in  London. 

Bulmer  and  others  expect 
Palm  will  include  with  the  ARM- 
based  Palm  OS  an  emulator  that 
will  let  users  run  existing  Palm 
applications  on  the  ARM  de 
vices,  which  are  likely  to  appear 
in  the  latter  half  of  the  year.  ■ 


LinuxWorld  Expo  heralds  enterprise  goodies 


■  BY  PHIL  HOCHMUTH 

NEW  YORK  —  While  the  25,000 
or  so  attendees  at  last  week’s 
LinuxWorld  Expo  ranged  from 
bearded  and  pimply  faced  Linux 
hackers  to  corporate  CIOs  in  pin¬ 
stripes,  one  message  resounded 
clearly  from  the  show:  Now  is  the 
time  for  enterprise  customers  to 
make  the  move  to  Linux. 

A  bevy  of  new  enterprise  prod¬ 
ucts  and  conference  panels  and 
tutorials  on  how  companies  can 
benefit  and  save  money  with 
Linux  were  among  the  confer¬ 
ence  highlights.  Adding  to  the 
notion  that  Linux  has  “arrived”  as 
a  prime-time  IT  entity  were  high- 
profile  keynotes  from  top  indus¬ 
try  CEOs  including  Hewlett- 
Packard’s  Carly  Fiorina  and  Com¬ 
puter  Associates’  Sanjay  Kumar, 
and  many  examples  of  high-end 
Linux  deployments. 

CA  introduced  23  manage¬ 
ment  products  for  controlling 
Linux. The  software  ranged  from 
tools  to  manage  an  entire  net¬ 
work  to  point  management 
products  for  storage,  security 
and  intranet  portal  hosting. 


HP  chief  Carly  Fiorina  called  her 
company's  proposed  merger  with 
Compaq  “a  combination  that's 
good  for  Linux." 

Some  of  the  company’s  major 
enterprise  software  available  for 
Linux  now  includes  the  whole 
eTrust  line  of  security  manage¬ 
ment  tools,  the  Unicenter  Net¬ 
work  and  System  Management 
application,  BrightStor  ArcServ 
Backup  and  CleverPath  enter¬ 
prise  portal  server. 

With  the  new  products,  CA 
aims  to  bring  management  to 
businesses  that  want  to  rein  in 


Linux  servers  running  on  the 
periphery  of  a  network  or  help 
companies  manage  a  network 
built  from  the  ground  up  on 
Linux,  says  Murray  Berkowitz, 
CAs  senior  vice  president  for 
advanced  technology 

The  pervasiveness  of  Linux 
technology  across  a  range  of  plat¬ 
forms  was  evident  on  the  show 
floor  as  vendors  had  Linux  run¬ 
ning  on  everything  from  wrist- 
watches  to  supercomputers.  HR 
Compaq  and  IBM  showed  off 
Linux  on  Intel  systems  in  clus¬ 
tered  systems  and  stand-alone  32- 
and  64-bit  Intel  systems,  while  Big 
Blue  also  trumpeted  its  Big  Iron 
as  a  way  to  consolidate  multiple 
Linux  servers  onto  one  platform. 

One  of  the  largest  crowds  on 
the  show  floor  was  at  the  Sharp 
booth,  where  attendees  tried  to 
get  a  peek  at  the  Linux-based 
Zaurus  SL-5500  handheld,  which 
runs  embedded  Linux  with  Java 
support  and  features  a  built-in 
BlackBerry-like  keyboard. 

HP’s  Fiorina  kicked  off  the 
show  in  front  of  a  packed  audi¬ 
torium  with  a  keynote  speech 
that  placed  Linux  alongside 


Windows  and  Unix  as  a  key 
enterprise  infrastructure  plat¬ 
form  going  into  the  future.  She 
also  called  her  firm’s  proposed 
merger  with  Compaq  “a  combi¬ 
nation  that’s  good  for  Linux,”  as 
each  firm  has  integrated  Linux 
product  and  support  offerings. 

In  a  separate  address,  an  IBM 
official  described  the  adoption  of 
Linux  across  the  company’s  serv¬ 
er  line  as  a  turning  point  for  IBM. 
“The  adoption  of  Linux,"  said 
William  Zeitler,  IBM  vice  presi¬ 
dent  and  server  business  head, 
“completely  reshaped  our  entire 
server  business.”  The  develop¬ 
ment  of  Linux  on  the  mainframe 
almost  single-handedly  turned 
that  product  around,  as  main¬ 
frame  sales  have  been  up  the 
past  five  quarters,  he  said. 

The  exhibition  was  also  a 
showcase  for  touting  produc¬ 
tion  Linux  deployments,  with 
companies  such  as  animation 
studios  Pixar  and  SKG  Dream¬ 
works,  eTrade,  and  the  invest¬ 
ment  banking  firm  Credit  Suisse 
First  Boston  all  detailing  their 
rollouts,  which  ranged  from 
high-powered  desktops  to  Web 


servers  and  the  use  of  Linux  on 
IBM  mainframes. 

Harry  Roberts,  CIO  of  Boscov’s 
department  stores  in  the  mid- 
Atlantic  region,  cut  his  support 
costs  in  half  by  moving  a  server 
farm  of  several  dozen  Microsoft 
Windows  boxes  onto  his  IBM 
mainframe. 

“For  every  10  to  12  servers  we 
have,  that’s  another  [staff  mem¬ 
ber]  1  need  to  run  and  maintain 
that  equipment,”  Roberts  said. 
“The  goal  was  to  move  to  one 
piece  of  iron  as  fast  as  possible,” 
as  a  way  to  cut  costs  when  man¬ 
agement  said  it  was  time  for 
some  belt  tightening,  he  added. 

Patrick  Carroll,  senior  systems 
engineer  for  L.L.  Bean  in  Free¬ 
port, Maine, took  a  more  gradual 
approach  to  Linux.  Carroll  said 
L.L.  Bean  saved  more  than 
$12,000  by  replacing  a  Sun 
SPARC-based  customer  e-mail 
response  server  to  a  Linux- 
based  mainframe.  The  main¬ 
frame  supporting  Linux  and 
running  Sendmail  pumps  out 
e-mails  to  customers  30  times 
faster  than  his  original  server,  he 
said.B 


software,  Inc. 


mm 


mm 


mm 


:■  --  0' 


■ 


ii 


is 


a’;®® 


m 


It  would  have  been  a  great  day  in  Detroit 


...too  bad  the  proposal  is  still  in  Denver 


Introducing  the  Xythos  WebFile  Server  3.2 
Internet-enabled  file  management  for  the  enterprise 

•  Ultimate  File  Access  -  anytime,  anywhere,  quick  &  easy 

•  Superior  Sharing  -  the  right  file  goes  to  the  right  people 
•  Safe  and  Secure  -  supports  existing  security  and  authentication  protocols 
•  Easy  Implementation  -  works  with  existing  network  and  storage  standards 

•  Lower  Costs  -  reduce  your  storage  management  costs  as  you  increase  productivity 

•  Free  IDC/Xythos  Whitepaper  -  discover  the  best  internet-enabled  file. management  software 
for  your  company 


Call  1  888  4XYTHOS  (1  888  499  8467)  or  visit  www.xythos.com/webfile24 
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VPNs  take  center  stage  at  ComNet 

Showdown,  service  announcements  prove  to  be  highlights  at  otherwise  guiet  show. 


fcfc  [AT&T  does]  a  huge  amount  of  business  in 
switched  voice.  Is  that  perhaps  causing  you 
to  go  a  bit  slow  on  supporting  voice  over  IP  in 
your  IP  VPN  platform?  1 1 

Arjen  Maarleveld,  head  of  products  at  Equant 

k  II  think  it  s  more  a  matter  of,  are  our  customers 
interested  in  buying  those  kinds  of  services?  But 
we  certainly  have  built  in  no  gates. If 

Johnathan  Cohen 

Director  of  advanced  IP  services,  AT &T 


PHOTOS:  STAN  BAROUH 


■  BY  TIM  GREENE  AND 
DENISE  PAPPALARDO 

WASHINGTON  —  VPNs  caught  the 
spotlight  at  last  week’s  ComNet  2002 
show,  with  a  spirited  VPN  service- 
provider  debate  and  the  debut  of  offer¬ 
ings  from  the  likes  of  WorldCom  and 
Sprint. 

Network  World's  VPN  Showdown,  which 
pitted  AT&T,  Equant,  Genuity  and  World¬ 
Com  executives  against  each  other,  at¬ 
tracted  a  standing-room-only  crowd  of 
530  —  one  of  the  stronger  showings  at  the 
conference,  which  drew  a  much  smaller- 
than-usual  attendance  in  light  of  industry 
and  economic  doldrums. 

While  customers  continue  to  rely  on 
frame  relay,  leased  lines  and  other  WAN 
infrastructure,  VPNs  are  coming  on 
strong,  as  evidenced  by  the  two-thirds  of 
U.S.  companies  that  IDC  says  are  already 
using  them  for  at  least  some  of  their 
remote  access.  VPN  service  spending  is 
expected  to  roughly  triple  over  the  next 
five  years,  from  $1.8  billion  to  $5.3  bil¬ 
lion,  according  to  IDC. 

To  meet  demand,  the  panelists  said 
their  companies  are  furiously  expanding 
their  VPN  offerings,  which  range  from 


fully  managed  services  based  on  IP 
Security  gear  placed  at  customer  sites,  to 
carrier-based  services  built  around 
Multi-protocol  Label  Switching  (MPLS). 

Equant  leapt  early  into  MPLS  VPN  ser¬ 
vices,  but  knows  that  some  customers 
don’t  want  them,  said  Arjen  Maarleveld, 
the  global  service  provider’s  head  of 
products.  “IPSec  has  its  place,  too,  so  we 
offer  both,”  he  says. 

Despite  agreeing  that  customers  want 


more  choice,  providers  took  a  few  shots  at 
each  other. “[AT&T  does]  a  huge  amount 
of  business  in  switched  voice.  Is  that  per¬ 
haps  causing  you  to  go  a  bit  slow  on  sup¬ 
porting  voice  over  IP  in  your  IP  VPN  plat¬ 
form?”  Maarleveld  asked  Johnathan 
Cohen,  director  of  advanced  IP  services 
for  AT&T: 

“I  think  it’s  more  a  matter  of,  are  our 
customers  interested  in  buying  those 
kinds  of  services?”  Cohen  replied.  “But 


we  certainly  have  built  in  no  gates.” AT&T 
does  offer  voice-over-IP  support  for  its 
managed  Internet  access  customers,  but 
not  its  VPN  customers. 

Later,  Genuity  Director  of  Product 
Strategy  John  Summers  said  that,  at  32 
countries,  WorldCom  offered  services  to 
the  lowest  number  of  nations  among 
companies  on  the  panel. 

WorldCom  indeed  delivers  to  cus¬ 
tomers  in  32  countries  over  its  own  net¬ 
work,  but  uses  other  vendors’  facilities  to 
reach  further  than  that,  said  Janel 
Crabtree,  WorldCom’s  director  of  global 
VPN  services.  “We’ve  expanded  that  to 
over  60  because  we  have  incorporated 
access  from  [third  parties],” she  said. 

In  response  to  a  question  from  Network 
World  Editorial  Director  John  Gallant, 
who  moderated  the  debate,  Genuity’s 
Summers  acknowledged  the  company 
has  taken  a  beating  on  Wall  Street,  as  evi¬ 
denced  by  a  stock  price  hovering  at 
around  $1.20  last  week,  down  from  a  52- 
week  high  of  $4.17.  But  Summers  said 
customers  should  be  confident  in  the 
company’s  long-term  prospects  given 
that  it  has  $500  million  in  funding  that 
should  help  it  get  into  the  black.  And  he 
See  ComNet  page  72 


Notebook 


From  VPN-ready  cabinets  to  translating  the  trickiest  of  terms. 


■  Where's  the  loot? 


There  was  a  serious  lack  of  razzle-dazzle  on  the  show  floor,  aside 
Ut  from  a  wizard  here  and  a  belly  dancer  there.  There  was  also  a 
lack  of  giveaways.  Many  attendees  roamed  practically  empty- 
handed,  compared  to  showgoers  in  years  past  who  had  to 
struggle  to  haul  around  vendor  logo-emblazoned  canvas 
bags  overflowing  with  tchotchkes.  Rather,  most  vendors 
seemed  to  settle  for  dishes  of  candy  —  mints,  chocolates, 
you  name  it.  We  could  have  used  a  few  vendors  giving 
away  toothbrushes  and  dental  floss  after  all  that. 


_  ( 


■  Ready  for  anything 

Electronics  cabinetmaker  Rittal  knows  how  to  jump 
on  a  trend.  Aware  that  VPNs  are  all  the  rage,  it 
posted  this  claim  next  to  one  of  its  sheet-metal 
equipment  enclosures:  “VPN  Ready.”  It’s  unclear  just 
what  you  have  to  do  to  a  cabinet  to  ready  it  for 
VPN  or  anything  else,  for  that  matter.  The  compa¬ 
ny  might  just  as  well  point  out  that  the  box  sup¬ 
ports  Windows,  Linux  and  Solaris,  too. 


■  Spam  smackdown 

The  “Spam  Wars"  session/debate  held 
Wednesday  certainly  lived  up  to  its  name.  Far 
from  devising  ways  to  solve  the  issue  of  unso¬ 
licited  bulk  e-mail,  panelists  couldn't  even  agree 
on  how  to  define  the  problem.  "There  are  levels 
of  permission,”  said  Ben  Isaacson,  executive 
director  of  the  Association  for  Interactive 
Marketing,  a  subsidiary  of  the  Direct  Marketing 


Association.  "You  buy  something  from  a  retailer,  and  they  have  permission 
to  contact  you.  If  you  say  you  don't  want  it,  then  they  should  stop." 

But  that  idea  didn’t  fly  with  other  panelists. 

"If  I  want  things,  I'm  perfectly  capable  of  asking  for  them,”  said  Kelly 
Thompson,  a  standards  and  practices  manager  with  Mindshare  Design  of 
San  Francisco.  “The  real  concern  is  that  the  growing  volume  [of  unsolicited 
e-mail]  is  causing  people  to  distrust  e-mail  and  to  distrust  engaging  in 
online  commerce,"  said  Ray  Everett-Church,  chief  privacy  officer  at  San 
Jose  ePrivacy  Group.  “That  distrust  will  kill  e-mail  and  the  Internet  faster 
than  anything  else." 


■  It's  all  in  the  translation 

As  if  explaining  terms  such  as  Multi-proto¬ 
col  Label  Switching,  VPN  and  voice  over  IP 
isn’t  hard  enough  to  do  with  words,  imagine 
trying  to  translate  their  meaning  with  your 
hands.  That  was  the  challenge  for  Jeffrey 
Bowden  and  Michelle  Lewis,  whose  job  last 
week  was  to  use  sign  language  to  translate 
keynote  and  other  ComNet  presentations 
for  deaf  members  of  the  audience. 
“Because  of  the  nature  of  electronic  com¬ 
munications,  members  of  the  deaf  commu¬ 
nity  can  excel  in  IT  fields,"  said  Bowden, 
who  tag-teamed  with  Lewis  every  20  min¬ 
utes  to  avoid  burnout. 

The  interpreters  said  their  translations  tend  to  be  more  delayed  than  usual 
when  dealing  with  highly  technical  presentations,  as  they  work  to  make 
sure  they  get  things  exactly  right.  Lewis  added:  “You  just  spell  out  the  let¬ 
ters  in  the  acronyms,  you  don't  need  to  know  what  they  mean." 
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Redline  aims  to  rev  up  Web  processing 


■  BY  TIM  GREENE 

WASHINGTON, D.C.—  Redline  Networks 
made  a  splash  at  ComNet  2002  with 
boasts  that  its  new  Web  acceleration  gear 
speeds  downloads  by  up  to  10  times  and 
reduces  the  need  to  buy  new  servers  as 
traffic  increases. 

PflMNET 

Redline  claims  its  T/X  2100  and  2400 
Web  acceleration  appliances  reduce  the 
number  of  bits  it  takes  to  transmit  a  page 
by  50%  to  74%,  saving  bandwidth  and 
processing  power.  The  devices  also  slash 
the  number  of  TCP  sessions  Web  servers 
have  to  handle,  increasing  server  perfor¬ 
mance  up  to  twentyfold,  according  to 
Sarah  Stanwyck,  Redline’s  vice  president 
of  marketing. 

The  devices  are  aimed  at  enterprise  cus¬ 
tomers,  but  hosting  providers  or  ISPs  also 
could  use  them  to  reduce  caching  and 
increase  performance. 

Online  comparison-shopping  portal  Biz- 
Rate.com  says  a  T/X  2400  compressed  and 
optimized  traffic  in  its  server  farm  so 
much  that  it  saved  the  company  thou¬ 
sands  of  dollars  per  month  on  Internet- 
access  bandwidth.  It  was  enough  to  pay 
off  the  $20,000  T/X  2400  in  two  months, 
says  Jody  Mulkey,  BizRate.com  s  vice  pres¬ 
ident  of  data  systems. 

Former  Dell  employees  came  up  with 
the  idea  for  Redline  after  working  on  a 
project  that  pointed  out,  among  other 
things,  that  setting  up  the  multiple  TCP  ses¬ 
sions  needed  to  download  Web  pages 
chews  up  processing  power  on  servers.  A 
separate  device  could  relieve  that. 

In  2000  they  won  seed  funding  from  for¬ 
mer  3Com  chief  Robert  Finocchio  and 
Ken  Oshman  —  the  “0”  in  ROLM,  the  pio¬ 
neering  PBX  company.  Redline  also 
landed  $10  million  from  Advanced  Tech¬ 
nology  Ventures. 

The  Campbell, Calif., company  has  a  pack 
of  competitors,  including  Packeteer,  Net- 
Scaler  and  PicturelQ,  says  Peter  Christy,  an 
analyst  with  NetsEdge  Research  Group. 
These  companies  approach  Web  accelera¬ 
tion  slightly  differently, some  using  caching 
to  offload  servers. 


Correction 


■  The  photo  that  accompanied  the  story 
"Unisphere  product  juggles  protocols" 
(Jan.  28,  page  37)  showed  the  incorrect 
product. 

■  The  “Look  before  you  leap  into 
802.11a"  editorial  (Jan.  28,  page  46) 
misidentified  the  company  with  which 
Proxim  is  merging.  The  correct  company 
is  Western  Multiplex. 


Redline  T/X  devices  don’t  cache,  but 
efficiently  retrieve  Web  pages  from 
servers  and  optimize  them  to  send  to 
requesting  PCs.  T/Xs  sit  between  Web 


farm  load  balancers  and  Web  servers.The 
devices  establish  links  between  down¬ 
stream  devices  requesting  Web  access 
and  corporate  Web  servers.  Without  these 


devices,  the  requesting  devices  would 
make  TCP  connections  directly  with  the 
Web  servers,  tying  up  the  servers  with 

See  Redline,  page  72 
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continued  from  page  1 

able  and  inexpensive  hardware 
with  performance  that  rivals 
Unix-based  systems.  And  users 
deploy  Linux  more  frequently  for 
business-critical  applications.  In 
fact,  Linux  deployment  is  so  hot, 
IDC  says,  that  9%  of  IT  budgets 
will  be  spent  on  deploying  and 
developing  the  operating  system 
and  applications  this  year. 

In  analyzing  competitive  prod¬ 
ucts,  Inzerillo  found  Linux  offered 
reliability  and  performance  com¬ 
parable  to  Unix,  and  ran  on  the 
same  Intel  platform  as  Windows 
NT/2000.  Inzerillo  says  that  even 
though  customers  can  spend 
$3,000  to  $5,000  on  an  Intel- 
based  server,  as  they  grow  they 
will  run  into  scaling  and  perfor¬ 
mance  problems  that  will  precip¬ 
itate  a  move  to  a  more  powerful 
Unix  box. 

“If  you’re  really  looking  at  the 
total  cost  of  ownership  and  try¬ 
ing  to  get  the  performance,  the 
best  reliability  and  integration 
with  applications,  Linux  is  just  so 
much  more  malleable  and 
robust  than  Windows  NT  or 
2000,”  says  Inzerillo,  who  runs 
Red  Hat  Linux  on  four  Dell 
PowerEdge  servers  attached  to 
90  terabytes  of  EMC  Clariion  stor¬ 
age.  In  addition,  Inzerillo  says  the 
number  of  systems  engineers  he 
needs  to  support  Linux  is  half  of 
what  his  NT  servers  require. 

Linux,  once  an  operating  sys¬ 
tem  that  users  viewed  with  sus¬ 
picion  for  enterprise  applica¬ 
tions  because  of  its  unconven¬ 
tional  support  and  develop¬ 
ment,  is  also  a  boon  for  just 
those  reasons.  Linux’s  reliance 
on  a  development  community 
means  changes  get  made  faster 


and  problems  are  fixed  more 
quickly,  says  Joe  Fbole,  technical 
director  for  Boscov’s  department 
store  chain,  which  has  57  stores  in 
the  mid-Atlantic  region. 

“If  you  have  open  source  [soft¬ 
ware],  people  look  at  it  very 
carefully  because  in  peer  review 
they  don’t  want  to  miss  any¬ 
thing,”  Poole  says.“If  you  put  your 
stamp  of  approval  on  something, 
it’s  your  own  reputation  on  the 
line. There  are  thousands  of  peo¬ 
ple  all  over  the  world  that  are 
doing  that.” 

Some  businesses,  such  as  Bos¬ 
cov’s  or  oil  exploration  company 
Amerada  Hess  in  Houston,  pin 
their  everyday  business  on  Linux. 
At  Boscov’s,  a  mission-critical 
invoice-matching  system  that 
compares  inventory  ordered  with 
inventory  received  runs  as  a 
Linux  application  on  an  IBM 
mainframe.  At  Hess,  Linux  plays 
roles  on  both  desktops  and  ser¬ 
vers  used  by  scientists  and  geolo¬ 
gists  to  explore  for  oil. 

Jeff  Davis,  a  senior  systems  pro¬ 
grammer,  is  in  charge  of  Linux  op¬ 
erations  at  Hess.  He  has  put  30% 
of  his  servers  and  workstations  on 
Linux.  Davis  says  the  division  of 
Hess  has  320  Linux  servers,  10 
Solaris  servers  and  several  hun¬ 
dred  NT/2000  servers  distributed 
among  200  users. 

“The  main  reason  we  started 
with  Linux  was  because  of  cost 
—  it’s  less  expensive  for  the  oper¬ 
ating  system,  but  it  also  let  us  use 
less-expensive  [Intel]  hardware,” 
Davis  says. 

More  than  two  years  ago,  Hess 
replaced  a  leased  IBM  super¬ 
computer  with  a  $130,000  clus¬ 
ter  that  runs  Red  Hat  Linux.  Red 
Hat  claims  the  migration  saved 
Hess  more  than  $2  million  on  a 
three-year  supercomputer  lease. 


“We  could  buy  off-the-shelf  sys¬ 
tems  rather  than  buying  special¬ 
ized  systems  from  IBM  or  Sun,” 
Davis  says.  The  engineering  and 
geophysicist  users  Davis  is  re¬ 
sponsible  for  also  run  an  open 
source  Linux  product  called  Xi- 
mian  Desktop  on  their  PCs. 

“These  [scientists,  geologists 
and  engineers]  previously  had 
Solaris  desktops,”  Davis  says.“The 
transition  from  Solaris  to  Ximian 
involved  literally  no  training.  I 
just  sat  with  the  users  for  about  5 
minutes  and  then  left  them  to 
their  own  devices.” 


Paul  Watkins,  network  analyst 
for  Newellco  Rubbermaid,  man¬ 
ufacturer  of  indoor/outdoor  stor¬ 
age  products,  Levelor  blinds  and 
Calphalon  pans,  says  Linux  has 
saved  his  company  more  than 
$100,000  per  year  that  they  previ¬ 
ously  spent  on  outsourced  per¬ 
formance  management. 

Watkins  runs  an  open  source 
performance-monitoring  pack¬ 
age  called  the  Multi-Router  Traf¬ 
fic  Grabber  (MRTG)  against  the 
nearly  250  Cisco  routers  and 
switches  that  link  the  190  loca¬ 
tions  in  Newellco’s  global  net¬ 
work.  MRTG  runs  on  Linux,  Unix 
and  NT. 

When  Newellco  originally 
brought  the  traffic  management 
in-house,  Watkins  put  it  on  an  NT 
server,  where  performance  suf¬ 
fered.  When  Newellco  was  look¬ 
ing  for  a  Linux  application  to  run 
on  its  IBM  eServer  zSeries  main¬ 
frame, Watkins  nominated  MRTG. 

“We  were  at  a  point  where  it 
took  over  a  half  hour  to  poll 
70%  of  our  network  from  a 
Windows  NT  server,”  Watkins 
says. “We  wanted  real-time  data, 
not  30-minute  old  data.  With 
Linux,  we  went  from  30  minutes 
to  under  three.” 

Linux  is  also  better  from  a  sta¬ 
bility  standpoint  than  NT/2000, 
the  United  Center’s  Inzerillo 
says.  “Under  Windows  NT  when 
things  go  south,  there’s  no  indi¬ 
cation  and  there’s  not  much  you 
can  do  to  figure  out  why  it  hap¬ 
pened.  With  Linux,  there’s  so 
much  more  reporting  and  tuning 


you  can  do  to  the  box.” 

Inzerillo  says  he  has  Linux 
servers  that  have  been  up  for  200 
to  300  days  and  have  given  him 
“huge  savings  [in  peace  of 
mind]  not  having  to  worry  about 
them." 

“On  Windows  NT/2000  servers, 
we  wind  up  just  prophylactically 
rebooting  servers  and  schedul¬ 
ing  downtime  once  a  week,” 
Inzerillo  says. 

Users  do  have  issues  with  Linux, 
support  being  the  main  one. 

The  support  for  Linux  is  a  con¬ 
cern  to  Malcolm  Fields,  CIO  of 


Hon  Industries, a  manufacturer  of 
office  furniture  and  gas/wood¬ 
burning  fireplaces  in  Muscatine, 
Iowa. 

“Anyone  who  manages  a  large 
data  center  has  to  have  some 
concerns  about  an  open  source 
application,  because  you  don’t 
really  want  to  be  in  the  busi¬ 
ness  of  maintaining  operating 
systems. 

“You  have  to  be  careful  about 
moving  to  open  source,  because 
at  some  point  you  are  going  to 
have  to  manage  it,”  he  says. 

In  Field’s  organization  more 
than  250  embedded  bar  code 
scanners  and  computers  are 
positioned  on  the  factory  floor 
at  35  sites,  where  nearly  half  of 
Hon’s  factory  workers  enter 
data  about  the  manufacturing 
process.  Systems  engineers  with 
Unix  backgrounds  use  Cal¬ 
dera’s  Volution  network  man¬ 
agement  software  to  manage 
the  devices. 

Watkins  says  he  hopes  the 
development  of  Linux  doesn’t 
splinter  into  a  bunch  of  incom¬ 
patible  versions  like  Unix  did.  He 
also  would  like  to  see  more  ven¬ 
dors  port  their  front-office  appli¬ 
cations,  such  as  Microsoft  Office, 
to  Linux. 

There  is  the  perception  that 
Unix  and  NT/2000  may  be  more 
supportable  than  Linux  be¬ 
cause  they  have  large  company 
support  organizations  backing 
them,  Inzerillo  says.  “A  lot  of 
people  may  have  problems  let¬ 
ting  go  of  their  production  envi¬ 


ronment  to  an  [operating  sys¬ 
tem]  that  has  nebulous  sup¬ 
port.  Support  is  still  a  big  safety 
blanket  in  a  production  envi¬ 
ronment  with  mission-critical 
systems.” 

As  for  the  future,  most  users 
plan  to  migrate  more  applica¬ 
tions  to  the  operating  system. 
Researchers  at  IDC  say  more 
than  2,300  enterprise-level  ap¬ 
plications  already  have  been 
ported  to  Linux. 

Newellco  is  considering  run¬ 
ning  some  databases  on  Linux 
and  already  has  a  few  CD-ROM, 


Web  and  DNS  servers  running 
on  the  package. 

And  at  Boscov’s,  Poole  says  he’s 
looking  to  move  as  many  servers 
onto  Linux  as  he  can. 

“Linux  has  the  potential  of 
becoming  a  good,  stable  operat¬ 
ing  system  that  more  people 
can  run  their  SAP  and  Pfeople- 
Soft  applications  on.  The  more 
of  those  applications  that  be 
come  available,  the  more  peo¬ 
ple  who  will  be  attracted  to  Li¬ 
nux,  not  only  because  of  its  sta¬ 
bility  but  because  its  a  highly 
secure  environment  on  which 
to  run  applications.”  ■ 


■  THIS  WEEK  S  QUESTION: 

What’s  the  name  of 
Apple  co-founder  Steve 
Wozniak's  new  com¬ 
pany,  which  is  a  play  on 
his  nickname  "Woz”? 

Answer  the  and  nine  addtwnal  questions 
online  and  you  could  win  S500!  Visit 

Network  World  Fusioo  and  enter  2349 

in  the  torch  j/ox. 

www.nwnision.com 


Consider  this 

Linux  business  users  say  there  are  a  few  things  to 
ponder  before  rolling  out  Linux,  including: 

Costs:  Look  at  total  cost  of  ownership.  IDC  says  users  can  save 
$307  per  year,  per  seat  by  running  Web,  intranet  and  other  appli¬ 
cations  on  Intel-based  Linux  servers  over  Unix  boxes. 

Training:  Unix-trained  systems  administrators  will  have  an  easier 
time  learning  Linux. 

Guarantees:  Buy  from  a  vendor  that  will  provide  you  with  a 
support  contract.  IBM,  Red  Hat  and  other  large  vendors  have  wide- 
ranging  support  available. 

Experiment:  Bring  Linux  in-house  slowly  —  start  with  a  pilot 
project  to  gauge  its  impact. 

Help:  If  you  are  deploying  many  Linux  machines,  consider  a 
management  package  such  asTurboLinux's  PowerCockpit. 
PowerCockpit  automates  the  configuration  and  deployment  of 
Linux  servers  —  making  your  IT  folks’ jobs  a  little  easier. 


■*  *  *  * 
**  *  * 

,  •» 


1 1  When  you  look  at  the  resources  and  what 
you  are  doing  with  them,  it's  clear  that  the  Linux 
decisions  we've  made  have  let  us  do  a  whole  lot 
more  with  a  whole  lot  less.  9  9 
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City 


State 


Zip 


Business  phone  ( _ ) _ 

FAX( - ). _ 

E-mail  address _ 

We  would  like  to  send  you  periodic  information  via  e-mail  on  3rd  party  networking  products/services. 
□  Check  here  if  you  DO  NOT  wish  to  receive  this  information. 


If  there  is  a  parent  company,  please  provide  name: _ 

□  My  home  address  is  also  my  business  address. 

Optional  delivery  address:  Enter  your  home  address  below  if  your  company  will  not  accept  delivery  at  your  business  address: 


Street  Address 


City  State  Zip 

Publisher  reserves  the  right  to  serve  only  those  individuals  who  meet  publication  qualifications.  ALL  questions  must  be 
answered.  Incomplete  forms  will  not  be  processed.  Free  subscriptions  available  to  qualified  US  applicants.  International  rates 
available  upon  request 
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Subscription  Application 


Please  indicate  the  Web/Security/LAN/Intemetworking/Wireless/Mobile/WAN  Equipment/ 
Carrier  Services  that  you  are  currently  involved  in  purchasing  or  plan  to  purchase: 

(check  ALL  that  apply)  A.  Currently  involved  in  purchasing  B.  Plan  to  purchase 


WEB - 

A  B 

□  01.D  Web  Servers/Software 

□  02.  □  Web  Traffic  Management 

□  03.  □  Electronic  Commerce  Tools 


SECURITY  - 
A  B 


□  04.  □  Web  Development  Tools 

□  05. 0  Web  Content  Management 

□  06.  □  Web  Collaboration/ 

Groupware 


□  07.  D  Web  Acceleration/Caching/ 

Load  Balancing 

□  08.  □  Web  Hosting  Services 

□  09.  □  Other 


□  10.  □  Firewalls 

□  11.  □  Anti-Virus  Software 

□  12.  □  Private  Key  Encryption  Tools 

LANs/INTERNETWORKING _ 

A  B 

□  19.  □  Fast  Ethernet 

□  20.  □  Gigabit  Ethernet 

□  21.  □  Layer  3-7  Switches 

□  22.  □  ATM  Switches 

□  23.  □  Routers 

□  24.  □  Network  Attached  Storage 

(NAS) 

□  25.  □  Storage  Area  Networks  (SANs) 

WIRELESS/MOBILE  - 

A  B 


□  13.  □  DES  Encryption  Tools 

□  14.  □  Authentication  Tools 

□  15.  □  Intrusion  Detection 


□  16.  □  Certificate  Authorities 

□  17.  □  Biometrics 

□  18.  □  Other 


□  26.  □  Storage  Backup 

(Optical,  Disk,  Tape,  RAID) 

□  27.  □  Network  Test/Diagnostic 

Tools 

□  28.  □  Uninterruptable  Power 

Supplies  (UPS) 

□  29.  □  Network  Interface  Cards 

(NICs,  PCMCIA) 


□  30.  □  Hubs/Intelligent  Hubs/ 

Stackable  Hubs 

□  31.  □  Cables.Connectors,  Baiuns 

□  32.  □  Wiringffiber  Systems 

□  33.  □  Net  Management  Systems 

□  34.  □  Voice  Over  IP  (VoIP)  Tools 

□  35.  □  Network  Analyzers 

□  36.  □  Other  Local-Area  Network/ 

Internetworking 


□  37.  □  Wireless  LANS 

□  38.  □  Wireless/Cell  Phones 


WAN  EQUIPMENT  - 
A  B 


A  B  A  B 

□  39.  □  Wireless  IAN  Extension  Tools  □  41.  □  PDAs 

□  40.  □  Mobile  Data  □  42.  □  Other  Remote/Wireless 

Equipment/Services 


□  43.  □  Frame  Relay  Equipment 

□  44.  □  Bandwidth  Managers 

□  45.  □  Bandwidth  Shaping/QOS 

Tools 

□  46.  □  VPN  Equipment 

□  47.  □  ATM  Switches 


CARRIER  SERVICES  . 
A  B 


□  48.  □  Voice/Video  over  IP 

Gateways 

□  49.  □  Modems 

□  50.  □  Cable  Modems 

□  51.  □  xDSL  Products 

□  52.  □  Diagnostic/Test  Equipment 


A  B 

□  53.  □ 

□  54.  □ 

□  55.  □ 

□  56.  □ 

□  57.  □ 

□  58.  □ 


DSUs/CSUs 

PBXs 

Call  Center  Tools 
Videoconferencing  Gear 
ISDN  Equipment/Services 
Other  WAN 
Equipment/Services 


□  59.  D  Internet  Access 

□  60.  □  Private  Lines 

□  61.  □  Frame  Relay  Services 

□  62.  □  ADSL/DSL 

□  63.  □  T-  l/T-3  Services 


□  64.  □  ATM  Services 

□  65.  □  Managed  Services 

□  66.  □  VPN  Services 

□  67.  □  LAN-Extension  Services 

□  68.0  OC-3/OC-12 


A  B 

□  69.  □ 

□  70.  □ 

□  71. □ 


Wavelength  Services 
Dark  Fiber 

Other  Carrier  Services 


None  of  the  above  (1 -71)  □  72.  □ 


What  is  the  principal  business  activity  at  your  location? 

(check  ONE  only) 


01.0  Manufacturing  (Non-Computer/ 
Communications  OEM) 

02.  □  Finance/Banking 
03.D  Insurance/Real  Estate/Legal 
04.  □  Health  Care  Services 
05.D  Hospitality/Entertainment/ 
Recreation 


09.0  Utilities/Process  Industries 
(Mining/Construction/ 
Petroleum  Refining/ 
Agriculture/Forestry) 

10.  □  Govemment/Military 

11. D  Consulting  (Independent)  * 
12.0  Education 


^.□Manufacturing  (Computer/ 
Communications/OEM) 

17.  □  Resellers/VARs/VADs/ 

Integrators/Distributors* 

(Computers/Communications) 

18. D  Other  (please  specify) 


06.  □  Media/TWCable/Radio/Print  13.D  Carriers/Voice/Data/ISP 


07. □  Retail/Wholesale  14.D  Web  Hosting/HSP 

Trade/Business  Services  15.DASP/SSP/MSP 

08.  □  Transportation 


'Attn  Consultants,  Integrators, 
Distributors,  Resellers:  Please  com¬ 
plete  form  based  on  ALL  clients  and 
your  own  business  needs 


2. 


p  s 


P:  What  is  your  primary  job  function?  (check  one  only) 

S:  What  additional  job  functions  are  you  involved  in?  (check  all  that  apply) 

PS  PS 


□  1.  □  Network  Management 

□  2.  □  CKVCTO/1S/IT/MIV 

Systems  Management 

□  3.  □  LAN  Management 


□  4.  □  Datacou/Telecom  Management 

□  5.  □  Intemet/Intranet/Web/ 

E-Commerce  Management 

□  6.  □  Engineering  Management 


□  7.  □  Corporate  Management 

(CEO,  COO,  CFO,  Pres.,  VP, 
Dir.,  Mgr.) 

□  8.  □  Consultant  (Independent) 

□  9.  □  Other  (please  specify) 


What  is  the  estimated  value  of  network  equipment  and  services  that  you  specify, 
recommend,  or  approve  the  purchase  Of? (Please  print  the  appropriate  number  code  on 
the  line  next  to  each  product  category.  Please  complete  ALL  categories  A-0.) 


1. 

$100  Million  or  more 

A 

Large  Systems 

H 

_ Intemet/Weh/E-commerce 

2. 

$50  Million  to  $99.9  Million 

(Mainframes/Minis) 

1 

Intranet/Extranet 

3. 

$25  Million  to  $49.9  Million 

B 

_ Desktops 

J 

4. 

$10  Million  to  $24.9  Million 

(Micros/Laptops/  Workstations) 

(including  Routers,  Switches) 

5. 

$1  Million  to  $9.9  Million 

_____  Mod  lie 

(including  PDAs,  Wireless) 

K 

_  Storage 

6. 

$100,000  to  $999,999 

D 

Servers 

L 

_ Remote  Access 

7. 

$50,000  to  $99,999 

E 

LANs 

M 

_ Peripherals 

8. 

Under  $50,000 

F 

_ WAN  Equipment 

N 

_ Software 

9. 

None  of  the  above 

G 

_ Carrier  Services 

O 

_ Serviee/Support  Services 

w1  HI  What  ls  ,he  ,0,al  number  ol  sites  lor  which  you  have  purchase  influence? 

(check  ONE  only) 

1.  □100 


1.0100+  2.  □  50  to  99  3.  □  20  to  49  4.  □  10  to  19  5.D2to9  6.  □  1  7.  □  None 


t\  Please  indicate  the  Systems/Peripherals/Software/Applications/Business  Services 

J. >  I  that  you  are  currently  involved  in  purchasing  or  plan  to  purchase:  (check  all  that  apply) 

A.  Currently  involved  in  purchasing  B.  Plan  to  purchase 

mTFMC/PPRIPUPRAK  . 

A  B 

□  01.  □  Laptops/Notebooks 

A  B 

□  06.  □  Fax  Servers 

A  B 

□  10.  □  Mainframes 

□  02.  □  Desktops 

□  07.  □  Remote  Access  Servers 

□  ll.D  Printers 

□  03.  □  Intel-Based  Servers 

□  08.  □  Video  Servers 

□  12.  □  Enclosures/Racks/Fumiture 

□  04.  □  Rise-Based  Servers 

□  05.  □  Print  Servers 

SnFTWARF/APPI  If  ATIONS 

□  09.  □  Mid-Range  Systems 

(including  workstations) 

□  13.  □  Other  Computers/ 

Peripherals 

A  B 

□  14.  □  DesktopVServer  Operating 

Systems 

□  15.D  Network  Management 

□  16.  □  Systems  Management 

□  17.n  Directory  Services 

□  18.  □  E-Mail 

□  19. □  Groupware 

BUSINESS  SERVICES 

A  B 

□  20.  □  Database  Management 

Systems 

□  21.  □  Customer  Resource 

Management  (CRM) 

□  22.  □  Enterprise  Resource 

Planning  (ERP) 

□  23.  □  XML  Tools 

□  24.  □  Desktop  Videoconferencing 

A  B 

□  25.  □  Middleware 

□  26.  □  Document  Management  Tools 

□  27.  □  Site  Metering  Tools 

□  28.  □  Software  Distribution  Tools 

□  29.  □  Data  Warehousing 

□  30.  □  Applications  Development 

Tools 

□  31.D  Other  Software/Applications 

A  B 

□  32.  □  Application  Service 
Provider  Services 

A  B 

□  33.  □  Systems  Integration/ 

Consulting 

□  34.  □  Education/Training  Services 

A  B 

□  35.  □  Other  Services 

A  B 

None  of  the  above  (1-35)  □  36.  □ 

g|r  \  |  Please  indicate  the  platforms  that  are  currently  installed/planned:  (check  all  that  apply) 

IJ  A  A.  Currently  installed  B.  Planned  for  purchase 

A  B 

A  B 

A  B 

□  OLD  TCP/IP  v4 

□  03.  □  SNA/APPC/APPN/LU6.2 

□  05.  □  NETBIOS/NETBUE1 

O  02.  □  TCR/IP  v6 

□  04.  □  Novell  IPX/SPX 

□  06.  □  NFS 

□  07.  □  Other  Network  Protocols 

A  B 

A  B 

A  B 

□  08.  □  Gigabit  Ethernet 

□  13.  □  Token  Ring/Fokcn  Ring 

□  18.  □  DSL 

□  09.  □  Switched  Ethernet 

Switching 

□  19.  □  ISDN 

□  10.  □  Fast  Ethernet 

□  14.  □  Layer  3-7  Switching 

□  20.  □  Frame  Relay 

□  ll.D  Ethernet 

□  15.  □  FDDI 

□  21.  □  Private  Line  Tl.  T3,  OC-3, 

□  12.D  ATM 

□  16.  □  Fibre  Channel 

OC-12 

□  17.  □  Wireless  LANs 

□  22.  □  Other  LAN/WAN 

Environment 

DESKTOP/SERVER  OPERATING  SYSTEMS 
A  B 

A  B 

A  B 

□  23.  □  Windows  2000 

□  28.  □  Intel  based  UNIX 

□  34.  □  Palm  OS 

□  24.  □  Windows  95/98 

□  29.  □  RISC  based  UNIX 

□  35.  □  Windows  CE 

□  25.  □  Windows  NT/Windows  2000 

(inch  SOLARIS) 

□  36.  □  Other  Network  Operating 

□  26.  □  Novell  (NetWare  5.X,  4.X, 

□  30.  □  IBM  MVS/VM/VSE/ESA 

System 

3.X,  2.X) 

□  31.  □  OS/400 

A  B 

□  27.  □  LINUX 

□  32.  □  Digital  VMS 

□  33.  □  Macintosh 

None  of  the  above  (1-  36)  □  37.  □ 

Continued  on  next  page... 


Continued  from  page  one... 


What  is  the  total  number  of  Servers/Clients  installed/planned  at  your  location/in  your 
entire  organization?  (check  ONE  boi  in  each  column) 


servers  .  .  n 

At  Location  Entire  Org. 

A  6 

□  1.  50,000+ 

□  2.  10,000  to  49,999  □ 

□  3.  1,000  to  9,999  □ 

□  4.  100  lo  999 

□  5.  50  to  99  □ 

□  6,  10  lo  49 

□  7.  1  to  9  □ 

□  8.  none  G 


CLIENTS  . 

Location  Entire  Org. 

C  D 

□  1.  50,000+ 

□  2.  10,000  to  49,999  □ 

□  3.  1,000  lo  9,999  □ 

□  4.  100  to  999 

□  5.  50  to  99 

□  6.  10  to  49 

□  7.  1  to  9 

O  8.  none  G 


What  is  the  estimated  number  of  employees  in  your  entire  organization/at  your 

location?  (check  ONE  in  each  section) 


A.  Entire  organization: 

1.  □  Over  20,000  5.  □  1,000  -  2,499 

2.  □  10,000-  19,999  6.  □  500  -  999 

3.  □  5,000  -  9,999  7.  □  499  or  less 

4.  □  2500  -  4,999 


B.  At  your  location: 

1.  □  Over  20,000 

2.  □  10,000-  19.999 

3.  □  5,000  -  9,999 

4.  □  2500  -  4,999 

5.  □  1,000  -  2,499 


6.  □  500  -  999 

7.  □  250  -  499 

8.  □  100-249 

9.  □  99  or  less 


Which  of  the  following  hardware  platforms  are  installed/planned  in  your  company? 

(check  ALL  that  apply) 


[  '  I  Whal  is  your  scope  and  involvement  in  purchasing  decisions  for  network  products 

and  services  for  your  enterprise? 

A.  Scope  (duck  ONE  only) 

CORPORATE/ENTERPRISE: 
l.P  Entire  Enterprise/  Division/Multiple 

Multiple  Enterorises  Divisions 

B.  Involvement  (check  ALL  that  apply) 

1. D  Create  Network/IT  4.D  Evaluate 

Strategy  Products/Services 

2. D  Recommend/Specify  5.G  Determine  the  Need 

Brand  6.G  None 

3. G  Approve  Purchase 

2.P  Multinational  4.G  Department 

Enterprise  5.0  None 

A  -  Servers 

1.  □  IBM  (Mainframes)  s-  □  Unisys 

2.  □  IBM  RS/6000  6-  O  H-P 

3.  □  IBM  AS/400  <■  □  Other 

4.  □  Compaq/Digitai/ 

Tandem 


8  -  Workstations/Desktops/Laptops 

1.  □  Sun  Microsystems  5.  □  Dell 

2.  □  H-P  6.  □  Gateway 

3.  □  CompaqUigital  7.  □  Fujitsu 

4.  □  IBM  8.  □  Other 


What  is  the  estimated  gross  revenue  of  your  entire  company/institution? 

(check  ONE  only) 


1.  □  $20  Billion  or  More 

2.  □  $10  Billion  to  $19.9  Billion 

3.  □  $1  Billion  to  $9.9  Billion 

4.  □  $500  Million  to  $999.9  Million 


5.  □  $100  Million  to  $499.9  Million 

6.  □  $50  Million  to  $99.9  Million 

7.  □  $10  Million  to  $49.9  Million 

8.  □  $5  Million  to  $9.9  Million 


9.0  $4.9  Million  or  Less 
10D  None  of  the  above 


For  faster  service,  subscribe  online  at: 

http://www.nwwsubscribe.com/b202 


For  which  areas  outside  of  the  U.S.A.  do  you  have  purchase  influence? 

(check  ALL  that  apply) 


1.  □  Europe 

2.  □  Asia 


□  South  America 

□  Australia 


□  Middle  East 

□  Africa 


□  Canada 

□  None 


SIGN  UP  and  Start  Immediately  Receiving  our 
FREE  Weekly  e-Newsletter  This  Week  on  NWFusion 
and  easily  stay  current  on  today’s  networking  challenges! 


□YES!  Start  my  subscription  immediately. 


My  e-mail  address  is: 


Your  colleagues  may  also  qualify  for  a  FREE  subscription! 

Please  list  below  names,  job  functions,  e-mail  addresses  and  phone  numbers  of  other  individuals  at  your  location  who  might  also  benefit  from  a  FREE  subscription  to  NBfWOfkWOlId 

*7  NAME 

NAME 

JOB  FUNCTION 

JOB  FUNCTION 

E-MAIL  ADDRESS 

E-MAIL  ADDRESS 

PHONE  NUMBER 

:  PHONE  NUMBER 

NAME 

’•  NAME 

JOB  FUNCTION 

JOB  FUNCTION 

E-MAIL  ADDRESS 

E-MAIL  ADDRESS 

PHONE  NUMBER 

PHONE  NUMBER 

... . . .  ra— 

FORM  0002 


NO  POSTAGE 
NECESSARY 
IF  MAILED 
IN  THE 

UNITED  STATES 


BUSINESS  REPLY  MAIL 

FIRST-CLASS  MAIL  PERMIT  NO  1752  NORTHBROOK  IL 


POSTAGE  WILL  BE  PAID  BY  ADDRESSEE 


PO  BOX  3091 

NORTHBROOK  IL  60065-9928 
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www.nwfusion.com 


■  A  Linux  operating  system  for  desk¬ 
top  PCs  developed  by  Corel  is  set  to 
make  a  comeback  in  April,  according 
to  the  start-up  that  licensed  the  tech¬ 
nology  last  year.  Founded  on  Corel's 
technology,  Xandros  is  preparing  to 
take  the  wraps  off  its  Linux  desktop 
operating  system.  Xandros  licensed 
Corel’s  Linux  distribution  in  August 
with  $10  million  in  backing  from  Linux 
Global  Partners,  an  incubator  that  has 
financed  many  Linux  software  mak¬ 
ers,  including  Ximian.  Xandros  has  yet 
to  announce  the  pricing  of  its  desktop 
product.  Xandros  will  also  offer  office 
productivity  applications,  Internet 
access  services  and  other  applica¬ 
tions  for  Xandros  Desktop,  www. 
xandros.net 

■  3Com  recently  unveiled  high-  and 
low-end  wireless  access  points  for 
802.11b  networks.  The  low-end  prod¬ 
ucts  are  designed  to  let  users  quickly 
set  up  small  and  very  inexpensive  11M 
bit/sec  wireless  LANs.  At  the  high 
end,  3Com  has  added  a  range  of  secu¬ 
rity  and  management  features  for 
enterprise  deployments.  Both  prod¬ 
ucts  include  an  HTTP  server  and  fea¬ 
ture  a  Web  browser-based  administra¬ 
tion  interface,  Once  the  device  is 
plugged  into  a  wall  outlet  the  built-in 
Ethernet  LAN  software  automatically 
finds  and  selects  the  least  crowded  of 
the  three  802.11b  channels  available  to 
it,  within  a  maximum  range  of  328 
feet.  The  company  says  the  device  will 
support  up  to  128  wireless  users.  The 
high-end  AP  8000  includes  several 
long-range  antenna  options  to  extend 
the  device's  range  to  1,000  feet  and  a 
program  called  Site  Survey  Utility 
that  figures  out  how  many  access 
points  are  needed  and  where.  Many 
security  and  encryption  schemes  are 
incorporated  in  the  device,  including 
the  basic  40-bit  wireless  encryption 
protocol  encryption  and  128-bit  shared 
key  encryption;  and  the  Remote 
Authentication  Dial-In  User  Service 
protocol,  which  works  with  a  central 
authentication  server.  The  AP  2000 
has  a  list  price  of  $230,  and  the  AP 
8000  is  priced  at  $600.  Both  are  avail¬ 
able  now.  www.3com.com 
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■  TCP/IP,  LAN/WAN  SWITCHES 

■  ROUTERS  ■  HUBS 

■  ACCESS  DEVICES  ■  CLIENTS 

■  SERVERS  ■  OPERATING  SYSTEMS 

■  VPNS  ■  NETWORKED  STORAGE 


CDNs  taking  on  enterprise  role 

Content-delivery  networks  promise  to  deliver  cost  savings  for  private  networks. 


Distributing  content 

Ten  things  your  enterprise  CDN  shouldn’t  be  without: 


■  BY  JENNIFER  MEARS 

Many  network  professionals  may  still 
think  of  a  content  delivery  network  as  sim¬ 
ply  a  system  of  public  caching  servers  that 
sit  at  the  edge  of  the  Internet.  But  increas¬ 
ingly  customers  are  finding  Web  traffic 
can  be  applied  to  a  private  WAN. 

However,  installing  an  enterprise  CDN 
(eCDN)  isn’t  as  easy  as  putting  caches  in 
various  locations  on  your  network.  It  can 
be  expensive,  and  it  can  get  complicated. 
But  if  you  determine  that  an  eCDN  makes 
good  business  sense  and  then  structure  it 
to  fit  in  with  your  existing  architecture,  it 
can  be  well  worth  the  effort,  observers  say. 

Take  Siemens  Medical  Solutions  Health 
Services.  The  healthcare  IT  division  of 
Siemens  delivers  applications,  profession¬ 
al  services  and  outsourcing  to  more  than 
5,000  healthcare  organizations  world¬ 
wide.  Siemens  Health  Services  wasn’t  sat¬ 
isfied  with  the  way  applications  per¬ 
formed  over  its  network.  It  was  tired  of 
having  extra  servers  standing  by  to  handle 
spikes  in  traffic  while  its  network  still  hov¬ 
ered  around  90%  availability 

So  it  installed  Cisco  content-delivery 
devices  to  push  content  out  to  the  edge  of 
its  network. With  its  internal  CDN,  Siemens 
Health  Services  boasts  99.998%  network 
availability  and  has  reduced  server  costs 
by  more  than  80%,  says  Michael  Alban, 
strategic  alliance  manager  at  Siemens 
Health  Services. 

“But  one  can  argue  that  content  delivery 
isn’t  for  everyone,”  he  adds.“It’s  a  question 
that  we  had  to  answer  ourselves.You  have 
to  look  at  content  delivery  and  ask  if  you 
have  an  existing  network  in  place  that  you 
can  take  advantage  of.  And  the  bottom 
line  is  what’s  the  business  value  you  gain 
by  deploying  your  own  content  network.” 

Content  considerations 

There  are  a  number  of  things  customers 
must  consider  before  investing  in  an  inter¬ 
nal  CDN.  One  of  the  first  things  to  think 
about  is  whether  your  business  has  appli¬ 
cations  that  require  content-delivery 
devices,  says  Dot  Fbwers,  advisory  net¬ 
work  specialist  for  Siemens  Health 
Services  and  a  Cisco  Certified  Inter¬ 
networking  Expert. 

Analysts  say  the  application  that  is  dri¬ 
ving  the  adoption  of  internal  CDNs  is 
streaming  media  for  online  training  or 

See  CDNs,  page  20 


“1.  Multiple  application  support. 

The  eCDN  is  an  overlay  to  the 
existing  network,  so  make  sure  it 
supports  things  such  as  content 
management,  video  on  demand 
and  live  broadcasting. 

2.  Comprehensive  architecture. 

There  should  be  a  core  server, 
edge  servers  and  a  database. 
Avoid  proprietary  systems. 

3.  Network  analysis.  It  should  have 
the  ability  to  automatically  check 
available  bandwidth,  link  speed  and 
hop  count. 

4.  Simple  content  publishing. 

It  should  be  easy  to  channel  content 
to  certain  user  groups  or  schedule 
downloads  for  certain  times. 

5.  Intelligent  content  distribution. 

The  eCDN  should  find  the  best  path 
automatically;  avoid  manually 
checking  each  network  link. 

SOURCE.  DIGITAL  PIPE,  CDN  FALL  2001 


Linux  users  to 

■  BY  DENI  CONNOR 

Users  wishing  to  run  Word,  Internet 
Explorer  or  other  Windows  applications  on 
non-Microsoft  platforms  can  finally  do  so 
with  software  that  a  consortium  of  open 
source  developers  will  roll  out  in  the  next 
three  months. 

Wine  1.0,  in  development  by  a  group  of 
voluntary  programmers  since  1993,  is  an 
implementation  of  Windows  3.X  and 
Win32  that  operates  on  top  of  Linux,  Unix 
or  X  Windows  workstations.  Other  features 
include: 

•  Support  for  Microsoft’s  Common  Ob¬ 
ject  Model  and  Distributed  COM  technolo¬ 
gies,  the  latter  of  which  lets  applications 
communicate  over  a  network  securely  and 
efficiently 

•  The  ability  to  mount  shares  on  multi¬ 
user  Samba  systems,  which  give  Linux 
desktop  users  access  to  file  and  print  ser¬ 
vices  that  use  Microsoft’s  Common  In¬ 
formation  File  System. 


0.  Dynamic  content  delivery. 

When  a  user  makes  a  request  the 
eCDN  should  automatically  identify 
where  the  user  is  located  and  find 
the  best  way  to  deliver  content. 

7.  Scalability.  Make  sure  the  eCDN 
can  handle  big  traffic  loads  and  can 
be  expanded  easily  if  necessary. 

8,  Security.  Ask  vendors  how  they’re 
locking  down  edge  servers  and 
make  sure  the  eCDN  can  handle 
things  such  as  content  encryption 
and  user  authorization. 

9,  Back-end  management  suite. 

A  policy-based  management  tool 
is  a  must  because  it  enables  you  to 
direct  how  the  eCDN  integrates 
with  the  rest  of  the  network. 

10.  Integrated  end-user  interface. 

Single-point  access  to  everything 
needed  to  run  the  eCDN  smoothly. 


toast  Wine 

•  The  capability  for  users  to  run 
Windows-based  Lotus  Notes  messaging 
clients  on  Linux  workstations. 

Companies  have  tested  prerelease  ver¬ 
sions  of  Wine,  with  some  using  Linux  and 
Wine  on  their  desktops  to  concurrently  run 
Linux-based  management  tools  and 
Windows-based  desktop  applications. 

“Once  [Wine]  is  stable  enough,  1  could 
roll  it  out  to  users  that  already  have  Linux 
desktops,”  says  Jacob  Kennedy  a  systems 
analyst  for  a  company  in  the  U.K.  that  he 
asked  not  be  identified.This  would  let  him 
deliver  Word,  Outlook  and  other  Windows 
applications  to  end  users  with  Linux  on 
their  desktops,  he  says. 

Several  companies, such  as  Codeweavers 
and  Transgaming,  will  offer  distributions  of 
Wine,  packaged  with  installation  scripts 
and  documentation. 

Wine  runs  on  any  version  of  Linux  and 
can  be  downloaded  from  winehq.com, 
wine.codeweavers.com  or  www.trans 
gaming.com. 


They  work  all  hours.  They 


expect  their  computers 
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Yes  you  can.  Introducing  Microsoft'  Windows'  XP 
Professional,  the  most  reliable  version  of  Windows 
ever.  Features  like  System  File  Protection,  System 
Restore,  and  Device  Driver  Rollback  add  to  its 
dependability.  Plus,  the  new  Remote  Assistance 
feature  lets  you  take  remote  control  of  a  user’s  PC 
and  perform  any  diagnostic  and  repair  operations  as 
if  you  were  sitting  right  there  in  the  user’s  chair. 
All  of  which  translates  into  fewer  help-desk  calls  and 
fewer  headaches.  With  Windows  XP,  you  can. 
www.microsoft.com/windowsxp/itpro 
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Acronyms  are  the  bane  of  our  IT  exis¬ 
tence.  They’ve  been  produced  in 
such  volume  that,  even  within  the 
networked  world  we’ve  ended  up  with 
duplicates  with  different  spell-outs:  for 
example,  NCP  referring  to  IBM’s  Network 
Control  Program  and  Novell’s  NetWare 
Core  Protocol.  But  now  network  vendors 
have  upped  the  ante  by  giving  us  VPN  and 
VPN.  What  makes  this  different  is  that,  in 
both  cases,  the  acronym  stands  for  virtual 
private  network,  but  the  references  can 
have  completely  different  meanings. 

That  was  the  case  during  our  recent 
Network  World/The  Tolly  Group  State  of 
the  LAN/MAN  tour.  During  the  course  of 
our  roundtable  discussion,  we  had  vendor 
speakers  proclaiming  the  benefits  ofVPNs 
and  meaning  different  things  —  and  both 


www.nwfusion.com 


Will  the  real  VPN  please  stand  up? 


were  correct. 

The  problem  is  that  VPN  is  a  generic 
term,  but  one  that  has,  over  the  years, 
acquired  a  fairly  specific  meaning  —  at 
least  by  those  in  the  network  security 
arena.  Now  leading-edge  Multi-protocoi 
Label  Switching  (MPLS)  technology  is 
delivering  a  capability  that,  though  radi¬ 
cally  different,  can  legitimately  be  termed 
VPN  as  well. 

So  when  we  hear  the  term  VPN  bandied 
about,  we  need  to  know  the  implied  mod¬ 
ifier  —  is  the  reference  to  an  IP  Security 
VPN  or  an  MPLS  VPN.Time  to  understand 
the  difference. 

In  its  most  generic  sense,  VPN  implies 
technology  that  brings  attributes  of  a  pri¬ 
vate,  leased-line  network  to  data  flows  that 
are  actually  running  across  a  public  or 
quasi-public  IP  packet  network.Two  of  the 
most  important  attributes  are  privacy  and 
predictability 

Early  on,  security  vendors  devised  a 
number  of  encapsulation/encryption 
approaches  in  an  effort  to  deliver  on  the 
promise  of  privacy.  The  Layer  2  Tunneling 
Protocol  and  the  Point-to-Point  Tunneling 


Protocol  were  early  efforts  promoted  by 
the  likes  of  Cisco  and  Microsoft. 

Ultimately,  and  thankfully,  the  industry 
converged  on  the  vendor-independent 
IPSec  standard  for  secure  tunneling.  IPSec 
provides  for  authentication  between  end¬ 
points  and  then  coordinates  the  flow  of 
encrypted  traffic  between  them. 

Because  any  third  party  seeing  your  traf¬ 
fic  would  see  only  the  encrypted  jumble, 
IPSec  lets  you  have  the  security  of  a  pri¬ 
vate  network  while  enjoying  the  flexibility, 
robustness  and  economic  benefits  of 
using  a  shared  network. 

Paradoxically,  an  IPSec  tunnel  is  not  a 
tunnel  at  all  —  not,  at  least,  in  the  “fixed” 
sense  of  having  all  traffic  belonging  to  a 
particular  session  following  the  same  set 
of  router  hops  across  the  network.  And 
that  is  where  MPLS  comes  in. 

The  data  paths  on  private  networks  are 
fixed. This  is  one  of  the  great  benefits  of  a 
circuit-based  approach  and  one  that,  until 
recently,  has  been  beyond  the  realm  of 
possibility  with  packet  networks. 

Without  such  predictability,  service 
providers  can’t  easily  deliver  on  service- 


level  agreements,  and  end-user  network 
architects  cannot  feel  comfortable  run¬ 
ning  important,  latency-sensitive  applica¬ 
tions  across  public  packet  networks. 

MPLS  solves  that  problem.  By  tagging 
traffic  as  it  enters  the  edge  of  a  WAN, 
MPLS-enabled  switch/routers  can  make 
certain  that  particular  flows  traverse  par¬ 
ticular  paths  across  a  backbone  network. 
The  best  part  of  this  is  that  MPLS  tagging 
can  be  generated  on  ingress  to  the  net¬ 
work  and  stripped  at  the  egress  point  with¬ 
out  having  to  involve  applications  at  all. 

But  MPLS  does  not  encrypt  your  traffic. 
What,  then,  if  someone  wants  the  pre¬ 
dictability  of  MPLS  with  the  security  of  an 
encrypted  IPSec  flow?  Because  neither 
interferes  with  the  other,  it  is  possible  and 
reasonable  to  run  an  IPSec  VPN  on  top  of 
an  MPLS  VPN.  What  more  could  you 
want? 

Tolly  is  president  of  The  Tolly  Group,  a 
strategic  consulting  and  independent  test¬ 
ing  company  in  Manasquan,  N.J.  He  can  be 
reached  at  htolly@tolly.com  or  www. tolly 
.com. 


CDNs 

continued  from  page  17 

companywide  CEO  addresses.  “Streaming 
media  is  the  killer  app  for  eCDNs,”  says 
Greg  Howard,  principal  analyst  at  HTRC 
Group. 

A  recent  HTRC  study  of  200  large  compa¬ 
nies  found  that  35%  handle  streaming 
today  and  42%  will  in  2002.  Of  companies 
doing  streaming,  more  than  half  will  build 
their  own  CDNs,  the  study  found. 

Other  applications  may  also  require  an 
internal  CDN. Siemens  delivers  clinical  and 
financial  applications  for  the  healthcare 
industry  It  was  delivering  a  mainframe 
application  with  a  browser-based  interface, 
but  because  the  application  used  a  2M-bit 
Java  applet  to  run  the  browser,  each  time 
an  update  was  needed  the  applet  had  to 
download,  putting  stress  on  the  network. 
Because  of  security  concerns,  a  public 
CDN  wasn’t  an  option,  Alban  says. 

First,  Siemens  looked  at  its  infrastructure 
to  determine  how  an  eCDN  would  fit. 
Powers  says  network  managers  should 
determine  whether  systems  can  easily  inte¬ 
grate  a  content-delivery  vehicle.  If  not,  it 
may  be  more  trouble  than  it  is  worth.  For 
Siemens  Health  Services,  the  integration 
was  easy,  she  says. 

“We  have  a  nice  modular-type  design  in 
our  infrastructure. We  have  an  IP  backbone, 
and  we  have  applications  that  are  very 
modulaifshe  says.“lt  was  a  real  easy  fit  from 
an  architectural  perspective." 

Application  support  is  key 

Application  support  is  an  important  part 
of  any  eCDN,  adds  Evan  Richman,  vice 
president  of  business  development  at  con¬ 
tent  networking  software  provider  Digital 
Pipe. That  means  making  sure  the  network 


can  support  things  such  as  video  on 
demand,  live  streaming  and  content  man¬ 
agement  tools.  Companies  should  also 
determine  whether  the  network  architec¬ 
ture  can,  or  will,  support  applications  such 
as  collaboration  and  database  replication. 

Another  thing  to  think  about  is  whether 
the  content  network  architecture  is  scal¬ 
able,  Richman  says.  “You’re  investing  in 
another  level  of  infrastructure,  and  you 
want  to  look  at  this  as  a  long-term  asset  that 
can  really  grow;’’  he  says. 

Siemens  Health  Services  is  expanding  its 
CDN  by  adding  content  switches  at  the 
core  of  its  network.  Its  content  networking 
devices  include  Cisco  content  switches, 
which  sit  next  to  Web  servers  and  in  front  of 
application  and  database  servers,  at  the 
core  of  the  network.  A  Cisco  content 
engine,  which  caches  content,  is  then 
placed  in  the  data  center  of  each  health¬ 
care  organization  accessing  applications 
from  Siemens. 

Other  issues 

Bowers  says  it’s  a  good  idea  to  take  an 
inventory  of  your  IT  team  and  determine 
whether  you  have  the  skills  to  configure 
application  delivery  on  a  CDN. 

“Our  server  team  has  an  in-depth  under¬ 
standing  of  the  rules  that  they  need  to  con¬ 
figure  for  the  delivery  of  content. The  rules 
are  based  on  information  that  is  deeper  in 
the  packet:  Layer  4  and  above,"  she  says.“l 
am  a  network  professional, and  it  would  be 
difficult  for  me  to  come  up  with  a  really 
good  set  of  Layer  4  and  above  rules  for  our 
applications,  so  1  work  with  our  server 
team.” 

Alban  notes  Siemens  did  not  have  to  add 
staff  to  support  its  eCDN. 

“Other  enterprises  might  not  have  the  lux¬ 
ury  So  it’s  an  important  thing  to  consider” 
he  says.Then  weigh  all  the  expense  against 


the  cost  of  adding  servers  and  adding 
potential  bandwidth.” 

Another  issue  companies  should  con¬ 
sider  when  installing  internal  CDNs  is  how 
the  content  network  devices  analyze  the 
network  and  route  content.  This  is  a  must 
for  eCDNs,  Richman  says,  because  most 
content  moving  over  an  eCDN  will  be  tar¬ 
geted  for  specific  users,  rather  than  being 
open  to  anyone. 

The  eCDN  architecture  should  include 
back-end  management  that  intelligently 
routes  content  and  integrates  with  other 
enterprise  systems,  and  an  integrated  user 
interface  that  lets  network  managers  keep 
an  eye  on  how  content  and  applications 


are  moving.The  bottom  line,  he  says,  is  that 
an  eCDN  should  make  a  network  manag¬ 
er’s  life  easier,  not  more  difficult. 

“You  shouldn’t  have  to  have  a  lot  of 
resources  to  deploy  and  manage  these 
things,”  he  says. 

Digital  Pipe:  www.digitalpipe.com 

More  online! 

How  content-delivery  tech¬ 
nology  is  predicted  to  play 
an  Important  role  as 
organizations  become 
more  Web-enabled. 
DocFinder:  7931 


Prototype  phone  boosts  speech 
recognition  quality 

■  BY  GEORGE  CHIDI,  JR. 

Motorola  and  speech  recognition  software  maker  SpeechWorks  International  have 
developed  a  prototype  phone  they  say  will  help  computers  better  decipher  wireless 
signals  for  clearer  transmissions. 

Mobile  speech  recognition  technology  generally  requires  that  a  speaker’s  voice  be 
transmitted  through  a  wireless  network  to  a  stationary  computer  for  processing. 

When  a  mobile  phone  user  is  in  a  bad  spot  in  a  network, say,  in  a  building  or  on  the  edge 
of  a  service  provider’s  coverage  area, some  voice  fidelity  is  lost..  A  computer  trying  to  per¬ 
form  voice  recognition  processing  on  a  garbled  transmission  would  be  more  likely  to  fail. 
The  limitations  of  wireless  phone  network  signal  transmissions  compound  the  problem. 
A  voice  call  cannot  use  the  same  redundant  transmissions  meant  to  guarantee  Internet 
packet  delivery 

Motorola  and  SpeechWorks’  prototype  is  meant  to  attack  the  signal  problem  at  the 
source.The  processor  cleans  up  the  voice  signal, performing  the  digital  equivalent  of  the 
signal.  A  server  running  SpeechWorks  software  can  process  the  clarified  signal  more 
easily. 

The  experimental  phone  uses  a  field-force  automation  application,  letting  a  traveling 
sales  representative  check  accounts  by  speaking  into  a  handheld  device. 

The  phone  could  hit  the  market  in  12  to  18  months,  the  companies  say. 

Chidi  is  a  correspondent  with  the  IDG  News  Service  s  Boston  bureau. 
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It’s  no  secret  that  higher-performing— and  more  demanding  — business  applications  and  technologies 
are  on  the  way.  So  how  do  you  stay  ahead  of  them  before  you  can  see  exactly  what’s  coming? 
Always  choose  PCs  powered  by  the  latest  Intel Pentium'*  4  processors— now  available  at  speeds  up  to 
2.20  GHz.  It’s  performance  with  purpose.  Visit  www.intel.com/info/pentium4  for  more  information. 
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Cisco  VMS  Version  2.0 


Cisco  upgrades 
security 
management 
suite,  but  tool 
integration 
lags. 


■  BY  JOEL  SNYDER,  NETWORK  WORLD  GLOBAL  TEST  ALLIANCE 

PN/Security  Management  Solution  Version  2.0  (VMS  2.0)  is  Ciscos  latest 
foray  into  security  and  VPN  management.  It  s  four  Cisco  management  tools 
in  one  box,  with  coordinated  installation  and  release  notes. 

Ciscos  last  attempt  at  bundling  these  tools  had  limited  success.  In  this  release, each 
stand-alone  product  performs  well. We  were  impressed  with  the  progress  Cisco  made 
in  firewall  and  VPN  tools  that  we  previously  reviewed  (www.nwfusion.com, 
DocFinder:  7926). 


However,  the  individual  products  are  far  from  integrated. 

VMS  Version  2.0  has  four  components: 

1  Cisco  Secure  Fblicy  Manager  (CSPM)  Version  3.0  is  a  new  version  of  the  company’s 
firewall  and  VPN  configuration  tool  that  generates  and  downloads  configurations  into 
Cisco  IOS  and  PIX  devices. 

2.  Intrusion  detection  is  managed  through  CSPM  Version  2.3,  which  has  been 
enhanced  to  support  both  network-  and  host-based  intrusion  detection  systems. 

3.  VPN  monitoring,  alerting  and  reporting  are  covered  in  a  separate  tool, 
CiscoWorks2000VPN  Monitor. 

4.  All  other  management  functions  are  part  of  CiscoWorks2000,  which  includes 
device  inventory  logging,  availability  software  management  and  configuration  control. 

CSPM  3.0  is  easy  to  use,  both  with  new  and  existing  devices.  (For  details  on  the 
products  we  used  to  test  VMS  2.0,  see  www.nwfusion.com,  DocFinder:  7935.)  First, 
you  define  your  network  topology  by  drawing  a  map  and  putting  in  Cisco  (and  non- 
Cisco)  devices.  Then,  you  use  a  simple  tool  to  define  rules:  what  traffic  is  allowed 
and  what  is  not. 

CSPM  3.0  uses  the  rules  you  create  to  generate  commands  for  all  the  affected 
devices,  automatically  computing  which  ones  need  to  be  changed  and  how.  CSPM 


Net  Results 


VPN/Security  Management  Solution  Version  2.0 

Company:  Cisco  Systems,  www.cisco.com  Cost:  A  license  for 
10  managed  devices  is  $8,000.  Pros:  Offers  simplified  management 
of  security  policy  across  multiple  networks;  defines  both  mesh 
and  hub-and-spokeVPNs  within  one  GUI;  PIX  configurations  with 
new  security  policies.  Cons:  Lack  of  coordination  and  central  directory  between 
product  components;  CSPM  Version  3.0  still  too  complex;  can't  build  VPNs 
without  thinking  in  firewall  terms  and  traffic  flows. 


What's  the  score? 

VPN/Security  Management 
Solution  Version  2.0 

Enterprise-quality  configuration  30% 

4.0 

Ease  of  use/documentation  25% 

3.0 

Scalability  20% 

3.5 

Management  15% 

4.0 

Performance  10% 

4.0 

TOTAL  SCORE 

3.65 

Individual  category  scores  are  based  on  a  scale  of  1  to  5.  Percentages  are  the  weight  given 
each  category  in  determining  the  total  score.  ■  Scoring  Key:  5:  Exceptional  showing  in  this 
ategory.  Defines  the  standard  of  excellence.  4:  Very  good  showing.  Although  there  may  be  room 
for  improvement,  this  product  was  much  better  than  the  average.  3:  Average  showing  in  this 
category  Product  was  neither  especially  good  nor  exceptionally  bad.  2:  Below  average.  Lacked 
some  features  or  lower  performance  than  other  products  or  than  expected  1:  Consistently  subpar, 
or  lacking  features  being  reviewed. 


3.0  downloads  the  changed  configurations  to  each  device  (either  automatically  or 
after  you  approve  the  changes)  and  you’re  done. 

CSPM  3.0  understands  your  network  topology  so  it  knows  which  devices  need  to 
be  updated  and  how.  Once  you’ve  taught  CSPM  3.0  your  network  topology, you  don’t 
have  to  worry  about  which  devices  are  in  the  path  between  different  kinds  of  traffic. 

CSPM  3.0  supports  fully  meshed  and  hub-and-spokeVPNs.  The  VPN  topology  is  a 
virtual  one,  layered  on  top  of  the  physical  network  topology.  You  define  VPNs  by 
adding  nodes  to  VPN  tunnel  groups  and  checking  a  box  on  any  firewall  rule  to  send 
that  traffic  through  the  VPN. 

This  style  of  VPN  brings  Cisco  up  to  speed  with  other  VPN  management  vendors, 
such  as  Avaya,  NetScreen  Technologies  and  Nokia,  but  there’s  a  catch.  It’s  quite  diffi¬ 
cult  to  simply  say  “tunnel  everything  between  every  VPN  node.”  CSPM  3.0  is  much 
more  focused  on  firewalling  traffic,  with  VPN  an  option,  than  on  building  VPNs  and 
firewalls  in  parallel. 

Some  pieces  of  VPN  management  are  still  missing.  Although  CSPM  3.0  lets  you 
select  from  the  three  Internet  Key  Exchange  authentication  schemes,  there  is  no 
help  for  the  difficult  task  of  defining  and  managing  certification  authorities,  certifi¬ 
cate  authority  trust  relationships,  or  requesting  and  managing  digital  certificates. 

Cisco  has  greatly  simplified  the  job  of  building  complex  access  lists  and  network 
address  translation  configurations  in  its  IOS  and  PIX  systems,  something  network 
managers  have  hoped  for. 

Not  so  much  integration 

In  this  release  of  VMS,  network-  and  host-based  intrusion  detection  system  devices 
are  managed  using  a  different  version  of  CSPM, Version  2.3,  which  must  run  on  a  dif¬ 
ferent  server  from  CSPM  3.0.  While  the  functions  of  managing  firewall/VPN  and 
intrusion  detection  are  generally  separate,  this  separation  can  be  a  problem  for  net¬ 
work  managers  who  implement  Cisco’s  “shunning”  feature. 

With  shunning,  intrusion  detection  system  alerts  actually  cause  configuration 
changes  in  firewalls  and  routers,  and  block  traffic  from  those  networks.  Because  shun¬ 
ning  is  handled  through  different  configuration  tool, network  managers  trying  to  debug 
and  analyze  configurations  using  CSPM  3.0  aren’t  looking  at  the  whole  picture. 

A  second  functionality  gap  occurs  between  the  VPN  Monitor  and  VPN  configura¬ 
tion  tools  in  CSPM  3.0. VPN  Monitor  is  a  Web-based  tool  built  into  CiscoWorks2000. 
With  VPN  Monitor, you  can  track,  report  and  alert  on  VPN  tunnels.  More  than  a  dozen 
statistics,  including  throughput,  resource  consumption  and  failure  rates,  can  be 
logged  and  graphed.  VPN  Monitor  also  generates  alerts  when  network  manager- 
defined  thresholds  are  crossed. 

CSPM  2.3,  CSPM  3.0  and  CiscoWorks2000  maintain  separate  device  inventories. 
This  means  that  if  you  define  a  VPN  in  CSPM  3.0, you  must  redefine  the  topology  in 
VPN  Monitor  by  hand.  If  you  want  devices  on  CSPM  3.0  to  participate  in  the  intru¬ 
sion  detection  system  configuration, you  also  have  to  redefine  the  topology  in  CSPM 
2.3.  In  this  case,  the  integration  that  VMS  2.0  provides  simply  means  that  all  the 
pieces  shipped  in  the  same  box. 

With  VMS  2.0,  Cisco  has  released  an  outstanding  suite  of  applications.  CSPM  3.0  is 
what  network  managers  have  been  waiting  for,  CSPM  2.3  adds  host-based  intrusion 
detection  system  functionality  to  the  existing  network-based  intrusion  detection  sys¬ 
tem,  and  CiscoWorks2000  comes  with  tools  no  Cisco  manager  should  be  without.  It 
would  be  nice  if  they  all  worked  together  a  little  better. 

Snyder,  a  Network  World  Test  Alliance  partner,  is  a  senior  partner  at  Opus  One  in 
Tucson,  Ariz.  He  can  be  reached  at  JoeiSnyder@opusl .com. 
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Our  new  OptiView™  Integrated  Network  Analyzer  makes  all 
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Introducing  the  Ml  500— the 
first  scalable,  stackable  backup  solution  that 
□  TOWS  with  your  customers. 


QuantumlATL  proudly  Introduces  the  Ml 500,  a  modular  automated  tape  library  that 
represents  a  breakthrough  solution  for  enterprises  large  and  small. 

Dog-Gone  Good 

The  Ml 500  maximizes  your  data  storage  and  integration  investment,  in  part  because  its  compact 
design  offers  the  greatest  density  per  cubic  foot  available  in  the  enterprise  class.  With  easily 
installed  hot-swappable  tape  drives  and  fans,  the  Ml 500  offers  reliable  data  backup  and  highly 
available  data  protection. 

Ml 500  Grows  Up,  Not  Out 

Utilizing  Super  DLTtape™  technology  and  the  exclusive  StackLink™  transfer  system, 


the  M1500  can  stack  up  to  10  modules  high.  The  Ml 500  accommodates  up  to 


20  tape  drives,  which  can  be  added  individually  or  in  multiple-drive  increments,  and  boasts  a 
capacity  up  to  44  TB.  As  your  storage  needs  grow,  modules  can  be  added  without  extending  the 
minimal  amount  of  floor  space  the  M1500  occupies.  In  other  words,  it  grows  up,  not  out. 


To  enter  a  drawing  for  a  FREE  Portable  DVD/CD  Player  and  to  learn  more 
about  how  the  Ml 500  can  grow  with  your  business,  visit  us  at  our 
Ml 500  Web  site  or  call  us  toll-free  at  (866)  827-1500. 
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Separate  linking  mechanism 
moves  cartridges  directly 
from  one  module  to  any  other 
in  less  than  3  seconds 


Visit  www.M1500.com  for  details. 


Quantum.  ATL 


P.O.  Box  57100,  Irvine,  CA  92619-7100 
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companies.  Specifications  are  subject  to  change  without  notice. 
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■  INTRANETS  ■  MESSAGING/GROUPWARE 

■  E-COMMERCE  ■  SECURITY 

■  NETWORK  MANAGEMENT  ■  DIRECTORIES 


■  IBM  recently  released  software 
that  makes  it  easier  to  integrate 
e-commerce  Web  sites  with  portals, 
letting  companies  offer  information 
and  transactional  capabilities  from  a 
single  user  interface.  Big  Blue  is  pro¬ 
viding  the  integration  capabilities  be¬ 
tween  its  WebSphere  Commerce 
Suite  Pro  5.1  and  WebSphere 
Portal  using  small  pieces  of  code 
that  add  commerce  functions,  such 
as  online  catalog  searches,  to  the  por¬ 
tal.  IBM  says  its  software  will  make 
online  corporate  offerings  more  effi¬ 
cient  by  putting  information,  collabo¬ 
ration  and  transactional  capabilities 
all  in  one  place.  The  software  is  avail¬ 
able  now.  Customized  installations  will 
likely  cost  between  $50,000  and 
$75,000.  www.ibm.com 

■  Quest  Software  has  consolidated 
several  of  its  Oracle  database  man¬ 
agement  tools  into  a  unified  product 
called  Quest  Central  for  Oracle. 

The  package  includes  tools  for  daily 
tuning  and  monitoring.  The  product  is 
composed  of  three  modules  for  stor¬ 
age,  performance  and  availability 
management.  Each  module  includes 
Quest  tools  related  to  those  areas, 
such  as  Spotlight  and  StorageXpert. 
Price  per  server  ranges  from  $11,000 
to  $110,000  for  the  performance  mod¬ 
ule  and  $5,000  to  $105,000  for  the  stor¬ 
age  pack.  The  product  will  ship  late  in 
the  second  quarter.  Pricing  informa¬ 
tion  is  not  available,  www.quest.com 

■  TruSecure  last  week  acquired 
managed  infrastructure  security  com¬ 
pany  Three  Pillars.  The  terms  of  the 
all-stock  deal  were  not  disclosed. 
TruSecure  offers  a  suite  of  security 
services  that  include  audits,  security 
recommendations  and  monitoring, 
and  will  integrate  Three  Pillars'  line  of 
remote  management  and  monitoring 
services  into  its  product  set.  Three 
Pillars  has  a  device  that  resides  at  the 
customer’s  location,  allowing  for  data 
collection  and  correlation,  meaning 
that  TruSecure  may  be  able  to  move 
into  more  proactive  security  services. 
www.trusecure.com,  www.three 
pillars.com 


A 


Sun  exec 
looks  at  Web 
services  and 
beyond 


Sun  Vice  President  James 

Gosling,  the  creator  of  Java,  knows  a  thing  or  two 
about  software  revolutions.  Gosling  recently  sat  down 
with  Network  World  Senior  Editor  John  Fontana  to 
talk  about  the  buzz  around  Web  services,  a  technolo¬ 
gy  being  hyped  as  a  savior  for  distributed  computing. 


You've  said  the  business  of  building  systems  that  talk  to  each 
other  has  been  around  for  a  long  time.  Does  Web  services  revo¬ 
lutionize  it? 


It’s  sort  of  yes  and  no. The  hard  part 
has  been  getting  people  who  are  com¬ 
petitors  to  agree  on  how  to  intercon¬ 
nect  things. The  XML  world,  because  it 
is  so  flexible  and  platform  neutral,  has 
gotten  a  lot  of  the  players  in  various 
games  to  say  this  would  be  a  good 
idea.  People  have  been  building  Web 
services  in  some  sense  for  years,  but 
the  thought  is  that  they  have  been 
doing  it  with  stone  axes.  People  who 
have  built  Web  sites  have  exposed 
their  service  using  something  that  is 
intended  for  direct  human  consump¬ 
tion  and  not  intended  for  consump¬ 
tion  by  other  systems.  There  has  been 
a  general  realization  that  there  is  actually  value  in  allow¬ 
ing  other  people  access  to  your  service  through  software, 
to  allow  somebody  else’s  software  to  talk  to  your  software. 

What  are  the  challenges  facing  Web  services? 

Certainly  security  is  an  issue,  and  security’s  evil  twin, 
authentication.  Actually  for  my  money,  the  really  hard 
problem  is  the  politics  behind  these  standard  schemas. 
Because  Web  services  only  work  if  you  can  get,  for  exam¬ 
ple, Travelocity  and  Expedia  to  agree  to  use  a  common 

See  Gosling,  page  28 


Upstart  software  firm  is  simply,  divine 


■  BY  JENNIFER  MEARS 

Mitsubishi  Electronic  Automation  has 
been  using  Participant  Server  content 
management  software  since  the 
summer  of  2000  to  streamline  the 
administration  of  its  business-to-busi- 
ness  Web  store  and  distributor  extranet. 
It’s  been  happy  with  the  technology,  but 
it’s  not  getting  the  software  from  Eprise 
anymore. 

Today,  Participant  Server  is  one  of  a  myr¬ 
iad  of  technologies  available  from  upstart 
software  and  services  firm  divine.  While 
divine  may  not  be  a  household  name 
today,  analysts  says  it’s  a  company  large 
customers  should  be  watching. 

Divine  is  the  latest  venture  for  Andrew 
Filipowski,  who  built  Platinum  Technolo¬ 
gies  into  a  software  powerhouse  before 
selling  it  to  Computer  Associates  in  1999. 
Filipowski  built  Platinum  through  acqui¬ 
sitions  and  he’s  taking  the  same  path 
with  divine. 

Filipowski  launched  divine  as  an  Internet 
holding  company  but  switched  gears  early 
last  year  with  the  purchase  of  enterprise 
information  portal  vendor  SageMaker. With 
that  acquisition,  divine  headed  down  the 


road  of  assembling  a  software  and  services 
company  designed  to  serve  Web-enabled 
businesses.  Mitsubishi  Electronic  Auto¬ 
mation  is  among  divine’s  customer  base  of 
20,000  companies. 

Divine’s  acquisitions  have  brought  it  tech¬ 
nology  and  expertise  that  run  the  gamut 
from  network  hosting  services  and  profes¬ 
sional  services  to  collaboration  and  con¬ 
tent  management.  Last  year,  divine 
acquired  professional  services  and  hosting 
firm  marchFirst,  content  management  and 
e-commerce  companies  Open  Market, 
Eprise  and  RoweCom,  and  managed  host¬ 
ing  provider  Data  Return,  among  others. 
Analysts  say  it  acquired  more  than  30  com¬ 
panies  last  year. 

Sue  Feldman,  an  analyst  at  IDC,  says 
companies  should  “absolutely”  be 
watching  divine,  especially  in  regard  to 
its  content-related  offerings.  Last  month, 
divine  acquired  assets  from  search  and 
content  vendor  Northern  Light.  With  the 
acquisition,  divine  offers  Northern 
Light’s  search  technology  and  its 
Special  Collection  online  library  of 
more  than  7,100  sources,  including 
Forbes,  Business  Week  and  The  New 
York  Times. 


■ 

PROFILE:  DIVINE 

Location:  Chicago 

Founded:  1999 

Products:  Professional  services, 
collaboration  and  content  manage¬ 
ment  software,  managed  services. 

Founder  and  CEO:  Flip  Filipowski 

Financing:  Posted  $13.7  million  in 
revenue  and  a  $111.5  million  net  loss 
for  the  quarter  ended  Sept.  30, 2001. 
Cash  on  hand  at  that  time  was 
reported  to  be  $175.8  million. 

Employees:  More  than  3,000 

Customers:  United  Airlines, 
CitiBank  and  J.C.  Penney. 

_ 

Fun  Fact:  Filipowski  launched  Divine 
as  a  holding  company  after  selling 
PlatinumTechnologies  to  Computer 
Associates  for  $3.5  billion. 

Feldman  says  content  management  is  a 
growing  concern  for  large  companies  as 
the  amount  of  digital  information 

See  divine,  page  28 
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See  what  I’m  saying? 


Getting  a  19th-century  building  ready  for  21st-century  business  is  no  small  feat. 
Microsoft®  Visio®  2002  can  help  you  get  up  for  the  task  at  hand.  Create  crystal-clear  network 
and  telecommunications  schematics,  space  plans,  even  detailed  HVAC  layouts,  to  quickly 
communicate  just  what  goes  where,  when,  and  how.  And  with  the  flexibility  to  save  Visio 
diagrams  as  Web  pages  or  to  use  them  in  Microsoft.  Office  documents  and  e-mail,  you 
can  make  sure  everyone  sees  a  job  well  done.  To  give  it  a  try,  visit  getvisio2002.com 
or  go  to  Internet  Keyword:  Microsoft  Visio.  Software  for  the  Agile  Business. 
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framework,  a  common  XML 
schema,  to  express  the  ser¬ 
vices  they  provide. 

Something  like  RosettaNet  is  doing 
by  producing  these  agreed  upon 
schemas  for  representing  data? 

Right.  Just  the  intercompany 
politics  of  getting  all  these 
guys  to  agree.  It’s  not  one 
major  source  of  pain.  It’s  sort 
of  diffused  pain,  because  the 
same  thing  has  to  happen  all 
over  the  place.  And  I  think  the 
wonderful  thing  is  that  it 
seems  to  be  happening.  I  had 
dinner  last  night  with  a  bunch 
of  people  from  the  oil  indus¬ 
try,  and  they  are  actively  work¬ 
ing  with  a  bunch  of  their  com¬ 
petitors  to  define  standard 
schemas.  And  that  is  not  a 
problem  that  any  computer 
vendor  can  fix. 

How  real  is  the  threat  of  complex¬ 
ity  to  Web  services?  People  always 
use  the  word  simple  when  describ¬ 
ing  Web  services  interfaces,  but 
when  you  start  to  talk  about  secu¬ 
rity,  transactional  integrity,  then 
things  can  get  complex. 

Complexity  is  a  huge  prob- 
lem.To  the  people  who  are 
doing  the  engineering,  it  is  a 
huge  deal. The  real  challenge 
for  the  vendors  in  the  Web  ser¬ 
vices  space  is  to  make  that 
complexity  simple.  For  some  of 
these  things,  there  is  actually 
an  unbelievable  amount  of 
“hair”  to  making  it  actually 
work.  But  you  have  to  expose  it 
in  a  way  that  makes  it  really 
simple. 


Where  is  the  intersection  of  Java 
and  Web  services?  How  does 
someone  doing  one  understand 
how  the  two  work  together? 

The  problem  is  actually  in  the 
phrasing  of  that  question, 
because  you  make  it  sound 
like  Java  and  Web  services  are 
two  separate  things  and  you 
have  to  make  them  work 
together. That  is  not  the  case. 
Java  in  a  sense  is  a  building 
material,  not  unlike  lumber 
and  nails.  Web  services  is 
essentially  a  style  of  putting 
them  together  to  build  struc- 
tures.The  fundamental  quali¬ 
ties  of  Java  are  still  there  but 
the  result  of  the  data  may  be 
expressed  in  XML  and  carried 
by  a  [Simple  Object  Access 
Protocol]  message. So  you  are 
basically  creating  a  shim  or  a 
piece  that  is  being  combined 
with  Java  so  you  can  pass  on 
that  functionality  to  some  other 
system.  One  of  the  things  that 
Java  was  designed  to  do  from 
the  very  beginning  is  network 
communication. There  is  this 
huge  stack  of  network  commu¬ 
nication  protocols,  such  as  IP 
[Simple  Mail  Transfer  Proto¬ 
col]  ,  [Internet  Message  Access 
Protocol]  and  [Post  Office 
Protocol]  and  then  you  get 
into  [Remote  Method  Invoc¬ 
ation]  and  [Common  Object 
Request  Broker  Architecture] . 
SOAP  is  just  another  one  of  the 
protocols  and  it  uses  XML  as  its 
data  representation. 

How  is  Sun's  view  of  Web  services 
different  than  Microsoft’s?  Are 
there  fundamental  differences  in 
what  can  be  accomplished  or  how 
they  are  used? 

I  think  at  that  level  our  views 
are  pretty  similar.  In  that  it’s 


something  that  people  can 
use  to  allow  their  systems  to 
interoperate  with  those  com¬ 
ing  from  the  outside,  and  on 
the  flip  side  of  that,  to  get  out 
and  interoperate  with  people 
on  the  outside. 

What  about  from  a  platform  per¬ 
spective  Java  2  Platform 
Enterprise  Edition  vs.  .Net? 

.Net  has  always  felt  like  an 
attempt  at  an  answer  to  J2EE. 
There  is  just  a  huge  amount  of 
facilities  available  on  the  part 
of  J2EE.  Actually,  I  think  there 
is  a  lot  more  in  J2EE  than  in 
.Net. Transaction  management, 
persistence,  database  integra¬ 
tion,  all  the  XML  stuff  is  there 
in  J2EE  and  has  been  for 
some  time.J2EE  is  a  market, 
not  a  product.There  are  a  lot 
of  vendors  out  there  that 
implement  J2EE.  And  there  are 
a  lot  of  add-on  products  that 
plug  into  J2EE.  By  the  magic  of 
the  way  the  platform  works, 
they  all  work  together. 

In  one  of  Gartner's  latest  [sur¬ 
veys],  it  listed  Sun  and  Oracle  as 
niche  players  in  the  Web  services 
market.  IBM  and  Microsoft  were 
listed  as  leaders.  What  is  your 
reaction  to  that? 

There  are  certain  truths  and 
certain  falsities.  In  terms  of 
things  that  are  certain  prod¬ 
ucts,  you  can  probably  fairly 
label  us  a  niche  player  in  my 
view.  Where  we  gain  most  of 
our  revenue  is  a  pretty  big 
niche,  however.  Most  of  it 
comes  from  selling  big  honk¬ 
ing  servers  in  the  infrastructure. 
But  from  an  industry  participa¬ 
tion  point  of  view,  we  are  all 
over  the  map  because  our  sys¬ 
tems  can’t  exist  as  islands.  ■ 


■  BY  CAROLYN  DUFFY  MARSAN 

Domain  names  with  the  .info 
extension  are  gaining  popularity 
among  corporate  customers, 
who  are  using  them  to  point  Web 
site  visitors  to  detailed  informa¬ 
tion  about  particular  products  or 
brands. 

Among  the  corporations  that 
recently  launched  Web  sites  with 
the  .info  extension  are  automak¬ 
ers  Subaru  and  Jaguar,  Australian 
network  firm  RedSheriff  and  the 
New  York  Metropolitan  Transit 
Authority  Many  of  these  compa¬ 
nies  have  purchased  a  .info 
name  for  a  particular  brand  — 
such  as  Subaru’s  wrx.info  for  its 
WRX  model  —  and  that  name 
points  to  the  part  of  the  compa¬ 
ny’s  existing  Web  site  with  infor¬ 
mation  about  that  brand. 

Afilias,  the  consortium  of  18 
domain  name  registrars  running 
the  .info  registry  says  more  than 
700,000  .info  names  have  been 
registered  since  they  became 
available  last  July 

“Eighty  percent  of  the  top  100 
brands  have  been  registered,” 
says  Roland  LaPlante,  chief  mar¬ 
keting  officer  for  Afilias.  “Now 
that  the  registry  has  been  live  for 
three  or  four  months,  we’re  see¬ 
ing  actual  Web  sites  being  built. 
We  knew  from  our  research  that 
[companies]  would  be  attracted 
to  .info  sites  because  they  feel 
they’re  more  educational  and 
informational  than  standard 
.com  names.” 

The  .info  names  also  appear 
easier  for  consumers  to  remem¬ 
ber.  The  New  York  Metropolitan 
Transit  Authority  replaced  its 
original  domain  name  —  mta. 
nycnyus  —  with  the  snappier 
mta.info  and  traffic  to  the  site 


What's  in  a  name? 


ballooned  from  200,000  hits  a 
day  to  3.5  million  hits  a  day  The 
new  mta.info  site  went  live  in 
October,  so  the  site  also  benefit¬ 
ed  from  an  increased  interest  in 
status  information  about  New 
York  City’s  bridges,  roads  and 
subway  systems  after  the  Sept.  1 1 
terrorist  attacks. 

“The  MTA  did  a  significant 
advertising  program  on  radio 
and  TY  which  they  couldn’t  have 
done  with  mta.nyc.ny.us  be¬ 
cause  it  was  too  complicated,” 
LaPlante  says.  “Now  they  have  a 
short,  memorable  name." 

Some  Web  sites  are  retaining 
their  original  .com  names  as 
they  purchase  .info  names. 
RedSheriff  split  its  Web  site  so 
product  and  service  informa¬ 
tion  are  on  redsheriff.info,  while 
other  corporate  information 
remains  on  redsheriff.com. 

Other  companies  are  purchas¬ 
ing  generic  sounding  .info 
names.  The  New  York  State 
Attorney  General’s  Office  set  up 
wtcrelief.info  as  a  Web  site  to 
compile  information  about  190 
organizations  that  are  accepting 
charitable  contributions  to  the 
World  Trade  Center  relief  effort. 

Overall, domain  name  sales  are 
falling  as  speculators  who  pur¬ 
chased  .com  names  during  the 
height  of  the  Internet  craze  in 
late  1999  and  early  2000  let  their 
two-year  registrations  expire.  Last 
fall,  the  number  of  .com  domain 
names  that  were  not  renewed 
surpassed  the  number  of  new 
.com  names  registered  for  the 
first  time  ever.  But  domain  name 
registrars  say  the  prospects  for 
the  new  top-level  domains  intro¬ 
duced  last  year  —  including 
.info,  .biz  and  .name  —  remain 
strong.  ■ 


Divine 

continued  from  page  25 

explodes.  Companies  that  don’t  handle  information 
well  can  suffer  millions  of  dollars  in  losses, she  says. 

“So  along  comes  divine  and  they  offer  information, 
plus  content  management,  plus  search,”  Feldman 
says.“Until  now,  for  the  most  part,  it  has  been  neces¬ 
sary  to  buy  a  separate  search  engine,  a  separate  con¬ 
tent  management  piece  and  separate  content.  With 
divine,  all  the  pieces  are  strung  together  and  there  is 
one  contact  point  for  your  information  systems. 

That  could  be  a  key  differentiator  as  the  company 
gears  up  for  some  pretty  stiff  competition,  experts 
say.  In  a  company  profile  she  wrote  on  divine  in 
December,  Patricia  Seybold  of 
Patricia  Seybold  Group  said 
divine  would  compete  with  IBM, 

Hewlett-Packard  and  “all  the  exist¬ 


ing  professional  services  and  systems  integration 
firms,”  such  as  Accenture,  PricewaterhouseCoopers 
and  Electronic  Data  Systems.  In  content-related 
areas.it  will  be  competing  with  companies  such  as 
Vignette,  Interwoven  and  IBM/Lotus,  she  said. 

Other  analysts  say  they  wonder  how  the  compa¬ 
ny  will  integrate  the  myriad  technologies  it  has 
brought  on  board.  “I’m  not  real  sanguine  they’re 
going  to  do  it.  At  least  not  within  the  time  frame 
they’re  talking  about,”  says  Robert  Lerner,  an  ana¬ 
lyst  with  Current  Analysis.  “But  1  may  be  proven 
wrong.” 

Hank  Barnes,  divine’s  general  manager  of  content 
delivery  and  aggregation,  says  the  company 
expects  to  integrate  its  products  within  the  next 
year  or  so.  He  says  most  of  the 
products  are  built  on  Java  2 
Platform  Enterprise  Edition. 
Divine:  www.divine.com 


Get  more  information  online. 
DocFinder:  7930 
••W.RwfKtM.CM 


New  .info  and  .biz  domains  gain  ground: 

Domain  name  registrations  (in  millions) 
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Wireless  email  that  means  business. 


Give  your  organization  the  jolt  it  needs  to  stay  ahead  of  the  competition.  Get  BlackBerry™  —  it’s  wireless  email 
for  the  enterprise.  So  your  team  can  communicate  wherever  they  go  -  and  you  can  relax  knowing  that 
BlackBerry  is  engineered  to  meet  your  strict  security  standards.  In  fact,  with  end-to-end  Triple  DES  encryption 
technology,  BlackBerry  allows  for  the  authentication,  integrity  and  confidentiality  of  all  incoming  and  outgoing 
messages.  BlackBerry  is  the  only  complete  solution  that  includes  powerful  wireless  handhelds,  enterprise 
server  software  and  nationwide  coverage.  You  might  say  it’s  wireless  email  that  fuels  your  business  day. 


WWW.BLACKBERRY.NET 
INFO®  BLACKBERRY.NET 


BLACKBERRY 

WIRELESS  EMAIL  SOLUTION 


©  2000-2001  Research  In  Motion  limited  (RIM)  All  rights  reserved  BlackBerry  is  an  end-to-end  wireless  email  solution  developed  by  RIM.  BlackBerry.  the  BlackBerry  logo,  the  “envelope  in  motion’  symbol,  RIM.  the  RIM  Wireless  Handheld  family  of  marks  and  the  RIM  logo  are  trademarks  or  registered  trademarks  of  RIM 


the  consolidation  of  your  three  data  centers  into  one,  when  word  comes  in  that  you're  buying  your  largest 

overseas  distributor,  adding  two  more  data  centers  to  the  already  complex 
equation.  Okay,  now  what? 

To  stay  competitive  in  an  environment  like  this,  you  have  to  be  able 
to  react  quickly  and  decisively  in  the  face  of  sudden  change.  It  would  help 
if  your  infrastructure  were  open,  resilient  and  manageable  enough  to  adapt 
when  you  need  it  to.  And  the  only  way  that's  possible  is  if  the  infrastructure 
is  built  to  work  around  your  needs,  not  the  other  way  around. 

HP  OpenView— our  multi-platform  management  software  — puts 
control  of  your  entire  infrastructure  within  easy  reach  of  your  keyboard. 
You  can  visualize  and  monitor  your  infrastructure— from  legacy  systems  to 
storage  to  Internet  services— from  one  central  location.  Helping  you  preempt 
problems  before  they  occur,  cost-effectively  maintain  high  service  levels  and 
protect  revenue  streams. 

HP  infrastructure  solutions  — servers,  software,  storage,  services  and 
beyond  — are  engineered  for  the  real  world  of  business.  Because  the  last  time 
we  checked,  that's  where  we  all  work.  Call  1.800.HPASKME,  ext.  246.  Or  visit 
hp.com/go/infrastructure. 

Infrastructure:  it  starts  with  you. 
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Enterprise  Applications 


A  technology  travelogue 


It  is  hard  to  think  of  column  topics  on  a 
good  week;  it’s  especially  hard  if  one  is 
in  the  middle  of  a  vacation.  My  wife 
and  1  are  on  an  eight-day  trip  around 
southern  California,  driving  all  the  way 
from  Los  Angeles  to  Monterey,  then  to  the 


Colorado  River  and  back.  During  the  last 
day  in  between  sightseeing  stops,  I’ve  been 
wracking  my  brain  trying  to  come  up  with 
some  insightful  topic  when  it  suddenly  hit 
me  that  many  of  the  things  we  have  been 
seeing  remind  me  (in  some  distorted  way) 


YOU  WANT  TO  MAKE  EXCUSES  FOR  YOUR 
WEBSITE,  THEN  CALL  CISCO  OR  F5 


www.nwfusion.com 


of  things  going  on  in  the  world  of  technol¬ 
ogy  and  the  Internet. 

Today,  we  stopped  in  Lake  Havasu  City, 
Ariz.,  to  see  the  London  Bridge.  Here  is 
something  that  was  a  technological 
marvel  when  it  was  built,  was  then 
declared  outdated  by  the  people  it  was 
designed  to  serve  and  was  finally  trans¬ 
ported  with  great  care  to  be  installed  in 
a  location  where  it  serves  no  actual 
function.  This  seems  to  be  the  perfect 
logo  for  those  people  who  want  to 
“improve”  the  Internet  by  adding  ATM 
flow  control  to  IP 

We  have  spent  most  of  our  driving  time, 
nearly  2,000  miles  so  far, on  small,  two-lane 
roads. We  have  been  very  lucky  because,  in 


We  stayed  in  Death 
Valley,  which  is  an  all- 
too-obvious  symbol  of 
the  high-tech  drought  we 
are  going  through. 


YOU  WANT  TO  HANDLE  A  MILLION  WEB  HITS, 

THEN  CALL  NETSCALER 


Request  Switch ™  6000  Series 


Your  reputation  is  your  website’s  infrastructure.  Which  makes  the  results  of  the 
recent  Internet  traffic  management  test  critically  important.  NetScaler  established 
one  million  simultaneous  active  Internet  connections.  F5  could  only  muster  280,000. 
Cisco,  “couldn’t  establish  any  significant  connections,"  according  to  eTesting  Labs. 
We  trounced  them  in  content  switching.  Then  we  man-handled  them  in  load 
balancing.  To  view  the  eTesting  Labs  NetScaler  Request  Switch  6500  Performance 
Comparison  for  yourself,  call  1-800-NETSCALER  or  visit  www.netscaler.com 


And  manage  web  traffic,  before  it  manages  you. 
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Innovation  to  Scale  the  Net 


spite  of  driving  “aggressively”  relative  to  the 
speed  limit,  almost  all  of  the  time  we  were 
alone  on  the  road.  We  only  had  to  deal 
with  a  few  of  those  special  twits  that,  hav¬ 
ing  decided  how  fast  they  want  to  go, 
somehow  contort  that  into  saying  that  it  is 
how  fast  everyone  should  go  and  engage 
in  whatever  blocking  necessary  to  be  sure 
that  this  is  the  case. This  type  of  person  is 
genetically  predisposed  to  drive  recre¬ 
ational  vehicles  or  serve  on  state  utility 


commissions. 


There  is  some  neat  stuff  in  this  part  of 
the  country.  We  just  went  through  Joshua 
Tree  National  Park,  named  after  a  tree  that 
looks  like  Picasso’s  idea  of  what  a  tree 
thinks  it  should  look  like  —  an  explosion 
of  limbs  going  in  all  directions, sort  of  like 
Enron’s  multitude  of  divisions. 

We  stopped  at  the  Hearst  Castle,  a  mon¬ 
ument  to  ego  and  veneer  in  that  the  core 
concrete  skeleton  is  crude  and  unfin¬ 
ished  and  covered  with  a  skin  that  makes 
it  look  impressive.  We  also  went  through 
Sequoia  National  Park  with  the  amazingly 
large  trees  that,  when  they  fall,  are  often 
hollow.  As  you  might  guess,  both  of  the  lat¬ 
ter  also  reminded  me  of  Enron. 

We  stayed  in  Death  Valley,  which  is  an 
all-too-obvious  symbol  of  the  high-tech 
drought  we  are  going  through.  But  it 
should  be  noted  that  Death  Valley  is  not 
all  that  wide,  just  a  few  miles  —  you  have 
to  insist  on  traveling  north  to  south  to  be 
in  the  valley  for  long.  Let’s  hope  that  our 
path  through  that  valley  is  the  short  one. 

Disclaimer:  Harvard  rarely  travels,  so 
the  above  travelogue  is  my  own. 


Bradner  is  a  consultant  with  Harvard 
University’s  University  Information  Sys¬ 
tems.  He  can  be  reached  at  sob@sobco 


.com. 


FREE  APC  Multiple  Outlet 
Rack-1 


to  the  first  100  entrants. 

All  entrants  will  receive  a 
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Be  one  of  the  first  100  to  mail  or  fax  this  completed 
coupon,  or  contact  APC,  and  you  will  be  entered  to 
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Call:  (888)  289-APCC 

use  the  extension  on  the  reverse  side 
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Legendary  Reliability' 


"Our  customers  feel  good  about 
the  fact  that  we  use  APC." 


COLOCATION 

BridgePoint  International,  Inc. 

Why  is  APC  the  best  choice  for  colocation  and  ISP  protection? 


WEB  HOSTING 


CABLE  MSO 


INFURMATIUNWctK 

500 


APC  was  named  to  the  2000 
InformationWeek  500  ranking  of 
the  top  IT  innovators  (09/11/00). 


APC's  award-winning  technology  and 
industry  leadership  continues  to  set 
the  standard  in  power  protection 
solutions.  APC's  services  and 
array  of  products  —  from 
surge  suppressors,  UPSs, 
cables  and  racks,  to  3-phase 
UPSs  and  DC  power  systems 
—  are  why  industry 
leaders  like  BridgePoint 
place  their  power  avail¬ 
ability  needs  in  the 
capable  hands  of  APC. 

"BridgePoint  International  Inc.  is 
a  leader  in  the  area  of  colocation 
centers.  Our  company  provides 
telehousing  centers  for  equip¬ 
ment  and  value-added  network 
services.  Our  clients  include 
Internet  Service  Providers, 
telecommunications  service 
providers  and  technology  com¬ 
panies  who  wish  to  leverage  the 
power  of  information  rich,  high¬ 
speed  telecommunications  net¬ 
works.  In  order  to  provide  our  cus¬ 
tomers  with  maximum  security  and 
protection,  we  invest  in  a  system  infra¬ 
structure  that  is  'bulletproof  and  always 
available. 

Basic  Requirement  Reliable  Power 

"We  approached  Symetrix,  an  APC 
Power  Specialist  in  the  Montreal, 

Quebec  area.  When  building  the 
colocation  centers,  redundancy, 
scalability  and  zero  downtime 
were  our  main  requirements. 


High  Availability  with  Low 
Implementation  Costs 

"We  initially  installed  APC's  Symmetra® 
Power  Arraf  s  at  each  site.  We  equipped 
each  Symmetra  with  the  APC  accessories 
needed  for  remote  monitoring  of  alarms 
and  environmental  conditions.  The 
potential  savings  in  future  service 
costs,  due  to  Symmetra  s 
user-serviceability,  really 
interested  us. 


mole  to  provide 
WitnJaTcomplete, 
enalto-end^solutioh. 
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"Once  the  colocation  rooms  had  been  established, 
we  needed  to  ensure  that  our  telecommunications 
service  would  be  available  at  all  times.  Only  a 
state-of-the-art  UPS  system  could  provide  us  with 
the  security  and  peace  of  mind  we  require.  APC's 
Silcorf  3-phase  UPS  solution  was  the  perfect 
answer  for  our  application. 

HVAC  and  DC  Add  Peace  of  Mind 

"We  have  recently  Installed  APC's  new  DC  power 
plant  and  NetworkAIR  air  conditioning  solutions 
into  our  sites.  APC  was  able  to  provide  us  with 
a  complete,  end-to-end  solution,  saving  us  time 
and  money. 

APC's  customer  service  is  the  way  customer  service 
is  supposed  to  be:  fast,  personal  and  efficient.  It 
is  the  same  way  we  treat  our  own  customers.  We 
consider  APC  a  valuable  member  of  our  team  and 
a  critical  factor  in  our  continued  success. " 
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BridgePoint 

INTERNATIONAL 


Marcel  Matteau,  Vice  President 

Engineering  &  Operations 
Colocation  Services 
BridgePoint  International,  Inc. 


DC  Power  Solutions  from  APC 
Telecommunications/ISP 


DC  Power  Systems  design/installation  j. 

& 

DC  rectifiers  and  power  shelves  with  i 
advanced  efficiency,  power  density  ffij*  j, 
and  temperature  range  performance 


Let  APC's  Legendary  Reliability’”  work  for 
you  as  it  has  for  over  10  million  customers, 
worldwide.  Whether  you're  an  ISP,  ASP,  or 
colocation  provider  like  BridgePoint,  APC 
provides  high  availability  solutions  for  your 
power  protection  needs.  Contact  APC  today! 


APC  is  a  proud  sponsor  of  the  Colocation  & 
Hosting  Association  and  a  member  of 
the  Internet  Service  Providers'  Consortium 
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THE  STRAIGHT  GOODS  ON  DATABASES 


~> 


ASE  lets  you  perform 
routine  maintenance 
operations  and  even 
change  configuration 
parameters  while  the 
database  is  online. 

You  can  transfer  users 
from  your  primary  system 
to  your  backup  system 
without  missing  a  beat. 
Even  if  they're  in  the 
middle  of  a  transaction. 
Your  employees  won't  even 
know  it’s  happening.  And 
neither  will  your  customers. 


and  prying  from  thieves  and 
vandals.  Sybase  ASE  provides  a 
row-level  security  mechanism 
that  allows  you  to  define  how 
your  database  is  accessed.  It’s  a 
feature  you’ll  find  missing  in 
most  competitive  products.  There's 
also  link  encryption  using  SSL 
and  PKI  certificates.  So  your 
business  is  safe  for  business. 


DOWNTIME  TIES  YOU  UP. 


If  your  e-Business  is  constantly 
online,  how  do  you  handle  routine 
DBMS  chores  like  maintenance? 


How  do  you  add  new  components 
and  resources  without  disrupting 
your  current  customer  transactions? 


Fortunately,  Sybase 
ASE  (Adaptive  Server 
Enterprise)  12.5  answers 
these  questions. 


Data  stored  in  the  database  can 
be  retrieved  as  XML  allowing  for 
easy  integration  of  your  existing 
information  with  your  new  Web 
applications. 


A  general  XML-Query  facility  (XQL) 
allows  you  to  easily  query  XML  data 
whether  it's  stored  in  the  DBMS,  a 
flat  file  or  even  a  URL  Bottom  line: 

faster  development  times, 
faster  access  to  the 
information  you  need. 


In  case  of  emergency, 

ASE's  proven  cluster 
architecture  provides 
fail-over  to  a  backup 
server  without  losing 
any  non-committed  data 
or  severing  a  single  user 
connection.  Bottom  line: 

ASE  delivers  continuous 
availability  to  everyone 
who  needs  it,  when  and  where 
they  need  it. 

INSECURITIES  BRING 
YOU  DOWN. 

ASE  responds  directly  to  your 
security  challenges  with  more 
security  features  than  a  Secret 
Service  detail.  Including,  but 
not  limited  to:  protection  from 
wiretaps,  accidental  disclosure 


XML  MEETS  A  DEAD-END. 

Sybase  ASE  makes  XML  rock  in  ways 
other  databases  simply 
don’t.  Sybase  ASE 
has  a  complete 
XML  framework 
for  storing, 
managing  and 
retrieving  XML 
directly  to  and 
from  the  database. 


If  e-Business  is  going  to 
be  a  critical  part  of  your 
success  this  year,  ASE 
has  a  critical  role  to ‘play. 


To  find  out  more  about  how 
Sybase  ASE  can  help  you  deploy 
and  manage  a  successful  e-Business, 
visit  www.sybase.com/breathe  or 
call  1-800-8-SYBASE. 


as 


i Sybase 


HIDDEN  COSTS 
BITE. 

Sybase  ASE  puts  the  bite 
on  hidden  costs. 

It  reduces  costs  by  the 
very  nature  of  its  24x7 
design. 

It  ensures  that  your 
business  never  goes  down. 

It  delivers  fast  backup 
and  recovery. 

It  utilizes  hardware 
resources  efficiently.  But 
even  before  you  get  to 
all  of  that  it  saves  you 
time  and  money  in  the 
traditionally  costly 
development  process. 


*2001  Sybase.  Inc.  All  rights  reserved.  All  trademarks  are  the  property  of  their  respective  owners. 


ASPs  look  to  bolster  security  offerings 


Locking  things  down 


In  the  fall  of  last  year,  IDC  interviewed  50  ASPs  to  find  out  what  type 
of  security  services  they  offer.  Here’s  what  they  had  to  say. 


Please  indicate  which  security  services  your  company  provides: 


i  Firewall 


■  BY  JENNIFER  MEARS 

Security  already  was  a  stumbling  block 
for  application  service  providers  intent  on 
convincing  companies  to  rely  on  remotely 
hosted  applications.  Now  with  security 
issues  getting  more  attention  because  of 
proliferating  viruses  and  increased  feelings 
of  vulnerability  after  Sept.  11,  ASPs  are 
renewing  efforts  to  provide  the  best  secu¬ 
rity  services  available. 

Because  it  is  an  emerging  market,  there 
are  not  standards  that  dictate  base  secur¬ 
ity  levels.  Analysts  suspect  these  standards 
will  emerge,  but  meanwhile  customers 
can  expect  ASPs  to  highlight  security 
offerings. 

Qwest  Cyber  Solutions  (QCS)  unveiled 


■  Equant  is  teaming  with  Racketeer 
to  offer  data  customers  its  Appli¬ 
cation  Performance  Analysis  ser 

vice,  monitoring  tools  that  could  be 
deployed  at  all  a  customer’s  network 
sites  or  areas  where  bandwidth  usage 
is  more  critical.  The  service  is  limited 
to  network  usage  and  performance, 
but  Equant  says  it  plans  to  roll  out 
specific  application-monitoring  sup¬ 
port  later  this  year.  This  feature  will  let 
users  monitor  how  a  customer 
resource  management  application 
performs  across  their  network. 

Equant  also  offers  network  monitor¬ 
ing  tools  from  Visual  Networks  and 
Concord  Communications. 

■  Research  in  Motion,  which  makes 
the  BlackBerry  handheld  device,  an¬ 
nounced  a  deal  last  week  with  AT&T 
Wireless  Services  to  offer  a  version 
of  its  device  with  e-mail  and  phone 
services  on  the  carriers'  high-speed 
data  network  in  the  U.S.  AT &T  Wire¬ 
less  will  offer  its  corporate  customers 
a  model  of  the  BlackBerry  Wireless 
Handheld  that  lets  users  place  a 
phone  call  using  a  plug-in  earpiece 
and  microphone.  The  service  will  be 
delivered  over  AT&T  Wireless'  GSM 
voice  network  using  General  Packet 
Radio  Service  technology. 


enhanced  security  services  last  week. 
This  release  follows  Corios  announce¬ 
ment  in  December  2001  that  it  was  rolling 
out  a  new  security  framework  for  enter¬ 
prise  customers.  Other  ASPs  say  they 
intend  to  closely  monitor  security 
advances  and  make  sure  they  provide  the 
latest  in  services. 

“Security  is  one  of  those  living,  breathing 
animals  that  changes  every  day  so  we’re 
always  looking  for  ways  to  make  our  clients 
more  secure  and  keep  their  data  more  se¬ 
cure,”  says  John  Kerr,  director  of  informa¬ 
tion  assurance  at  USinternetworking. 

Across  the  board,  ASPs  serving  large 
companies  and  delivering  complex  appli¬ 
cations  provide  a  standard  fare  of  man¬ 
aged  firewalls,  intrusion  detection,  net¬ 
work  security,  user  authentication  and 
VPN  services.  Some,  such  as  Corio,  partner 
with  managed  service  providers;  others, 
such  as  USi,  provide  much  of  the  security 
on  their  own. 

Nevertheless,  security  remains  one  of  the 
largest  hurdles  to  organizations  buying  into 
ASPs.  Many  companies  perceive  that  as  a 
vulnerability  even  though  analysts  and  cus¬ 
tomers  agree  ASPs  often  provide  better 
security  than  a  company  could  deploy  on 
its  own.  Part  of  the  reason  for  the  appre¬ 
hension  is  the  complicated  ASP  model, 
which  involves  not  only  remotely  hosting 
data,  but  also  transferring  that  data  across  a 


■  BY  MICHAEL  MARTIN 

Verizon  Wireless  launched  a  high-speed 
wireless  data  service  last  week  that  is 
capable  of  supporting  transfer  rates  of  up 
to  144K  bit/sec,  about  10  times  faster 
than  wireless  transfer  rates  on  existing 
networks. 

Called  Express  Network,  the  service  is 
available  in  several  large  cities  on  the  East 
and  West  coasts. 

While  Verizon  may  be  the  first  carrier  to 
market  with  a  service  supporting  higher 
wireless  data  transfer  rates  in  a  broad  mar¬ 
ket  launch,  other  providers  likely  won’t  be 
far  behind,  says  Eugene  Signorini.an  ana¬ 
lyst  with  The  Yankee  Group. 

“Sprint  has  plans  to  launch  a  high-speed 
service  in  Q2,”he  says.There  may  be  a  bit 


network  to  end  users.  Many  ASP-hosted 
applications  are  integrated  into  enterprise 
systems,  another  doorway  for  possible  net¬ 
work  breaches. 


of  a  market  advantage  in  getting  very 
early  adopters,  but  a  lead  time  of  a  cou¬ 
ple  of  months  isn’t  going  to  make  a  big 
difference.” 

AT&T  Wireless  also  has  tested  its  3G 
wireless  services  in  select  markets  since 
last  year.  While  Verizon  and  Sprint  base 
their  3G  networks  on  lxrtt,  which  is  based 
on  Code  Division  Multiple  Access  tech¬ 
nology,  AT&T’s  wireless  network  will  be 
based  on  the  GSM  communication  stan¬ 
dard  that  European  carriers  favor. 

Currently,  wireless  networks  support 
transfer  rates  of  about  14K  bit/sec,  a  far  cry 
from  the  144K  bit/sec  Verizon  says  its  net¬ 
work  can  support.  However,  Verizon  offi¬ 
cials  say  users  initially  should  expect  to 
get  average  speeds  between  40K  bit/sec 
and  60K  bit/sec. 


Still,  hundreds  of  companies  are  using 
ASPs  and  fueling  a  fast-growing  market. 
Large  companies  with  sensitive  data, such 

See  Security,  page  36 


Verizon  bills  the  new  wireless  network 
as  a  3G  implementation,  but  at  144K 
bit/sec  under  ideal  circumstances,  Ex¬ 
press  Network  is  just  a  step  on  the  path  to 
true  3G,  which  should  support  speeds  of 
3M  bit/sec  to  5M  bit/sec.  U.S.  carriers  are 
not  expected  to  achieve  true  3G  speeds 
until  about  2004. 

Verizon  is  promoting  the  Verizon  Wire¬ 
less  2235  Kyocera  as  its  Express  Network 
handset.The  Kyocera  unit  supports  a  wire¬ 
less  application  protocol  browser  and 
two-way  text  messaging.  By  also  purchas¬ 
ing  a  Mobile  Office  Kit  from  Verizon,  users 
can  hook  their  laptops  up  to  the  2235 
handset  and  use  the  handset  as  a  wireless 
modem. 

The  Sierra  Wireless  AirCard  555  is  the 

See  Wireless,  page  36 


Verizon  Wireless  gets  closer  to  3G 

Other  service  providers  not  far  behind,  analysts  say. 
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EYE  OH  THE 
CARRIERS 

Lisa 

Pierce 


Despite  the  marketing  rhetoric 
around  3G,  all  major  U.S.  wireless 
service  providers  are  in  the 
process  of  deploying  2.5G  mobile  data 
networks. 

1  appreciate  their  reasoning  —  2.5G  data 
speeds  are  two  to  three  times  faster  than 
2G  under  real-life  conditions. 

All  nonproprietary  services  already 
introduced  in  other  parts  of  the  world 
and  being  deployed  in  the  U.S.  now  are 
part  of  the  long-term  movement  by  wire¬ 
less  services  providers  away  from  circuit- 
switched  technology  (1G  and  2G  ser¬ 
vices)  toward  packet-switched  technol¬ 
ogy  to  support  voice  and  data  services 
(3G).  Because  3G  packetizes  voice  and 
data,  it  requires  much  faster  bandwidth 
than  can  be  supported  by  the  services 


2.5G  service  deployments  gather  momentum 


being  introduced  now.  The  International 
Telecommunications  Union  requires  that 
3G  services  deliver  2M  bit/sec  to  a  mobile 
device  while  stationary.  In  contrast,  the 
maximum  bandwidth  supported  by  2.5G 
Code  Division  Multiple  Access  (CDMA)- 
based  lxrtt  service  to  a  stationary  device 
is  153K  bit/sec. 

Similarly,  GSM-based  2.5G  Global 
Package  Radio  Service  (GPRS)  tops  out 
at  115K  bit/sec.  But  both  the  GSM  and 
CDMA  versions  of  these  technologies 
also  support  upgrades  and  overlays  to 
support  bandwidths  between  2.5G  ser¬ 
vices  and  3G  services.  Bandwidth  for 
Enhanced  Data  for  GSM  Evolution  and 
CDMA-based  3xrtt  services  top  out  about 
at  512K  bit/sec. 

However,  users  should  have  modest 
expectations  regarding  phase  one  2.5G 
throughput  because  the  bandwidth 
experienced  with  these  services  under 
real-life  conditions  is  significantly  lower 
than  the  maximum.  Although  lxrtt 
devices  can  support  the  maximum 
speed, the  experienced  bandwidth  while 
stationary  is  less  than  half  —  currently 


averaging  between  40K  bit/sec  and  64K 
bit/sec  under  real-life  conditions.  The 
peak  speed  of  current  generation  GSM- 
based  2.5G  devices  is  even  less  —  about 
25%  of  peak  bandwidth.  Relative  band¬ 
width  also  degrades  as  the  distance 
between  a  mobile  device  and  transmit¬ 
ter  increases.  Application  performance 
can  be  improved  with  the  use  of  com¬ 
pression,  but  depending  on  the  require¬ 
ments  of  the  application,  may  compen¬ 
sate  only  partially  for  the  lack  of  higher 
bandwidth. 

Various  U.S.  providers  have  different  ser¬ 
vice  introduction  plans.  Looking  at  those 
that  currently  have  double-digit  2G  mar¬ 
ket  share,  Verizon  Wireless  introduced  its 
lxrtt  service  last  week  and  made  it 
immediately  available  to  about  20%  of  its 
network  footprint. 

Its  plans  are  quite  aggressive,  as  the 
company’s  CTO  says  he  wants  to  have 
lxrtt  service  deployed  to  100%  of  its 
combined  digital  and  analog  footprint 
before  the  end  of  next  year.  Sprint  PCS 
had  intended  to  make  lxrtt  service 
available  to  a  limited  number  of  serving 


areas  by  the  end  of  last  year,  but  now 
says  it  will  make  it  available  to  100%  of 
its  base  this  summer.  AT&T  Wireless 
began  introducing  GPRS  last  July  and 
has  deployed  it  in  20  U.S.  states  to  date. 
It  has  gone  on  record  on  many  occa¬ 
sions  that  it  intends  to  get  2.5G  service 
deployed  to  100%  of  its  digital  base  by 
year-end.  And  Cingular  is  deploying 
GPRS  in  Puerto  Rico,  its  initial  market, 
right  now. 

When  considering  current  2.5G  ser¬ 
vices  and  future  enhancements,  im¬ 
portant  issues  include  service  availabil¬ 
ity,  device  throughput,  security,  applica¬ 
tion  design  and  price.  With  their  intro¬ 
duction  by  multiple  providers,  com¬ 
panies  finally  can  begin  to  evaluate 
their  applicability  and  value  to  their 
businesses. 

Whatever  they  may  be  called  by 
providers,  these  services  are  indeed  a 
welcome  arrival  in  the  U.S. 

Pierce  is  a  research  fellow  at  Giga  In¬ 
formation  Group.  She  can  be  reached  at 
lpierce@gigaweb.  com. 


Wireless 

continued  from  page  35 

other  method  users  can  employ 
to  connect  to  Express  Network. 
The  card  fits  into  a  standard  PC 
card  slot  on  a  laptop  or  other 
computing  device  and  acts  as 
modem  and  mobile  phone. 

Verizon  also  unveiled  a  part¬ 
nership  with  Accenture  last 
week  that  will  involve  both 
companies  selling  integrated 
application  and  wireless  offer¬ 
ings  to  businesses. 

Accenture,  formerly  Anderson 
Consulting,  will  handle  the  inte¬ 
gration  of  mobile  enterprise 
applications,  which  could  in¬ 
clude  customer  relationship 
management  software  and  in¬ 
ventory  information  with  Veri¬ 
zon’s  Express  Network. 

Express  Network  is  available  in 
about  20%  of  Verizon  Wireless’ 
overall  footprint.  Verizon  says  it 
hopes  to  have  most  of  its  points 
of  presence  upgraded  to  sup¬ 
port  Express  Network  by  year- 
end. 

Verizon  Wireless,  which  is 
jointly  owned  by  Verizon  and 
Vodafone,  an  international  mo¬ 
bile  telecom  outfit  in  the  U.K., 
has  about  29  million  customers. 

Most  potential  3G  users  likely 
will  wait  until  they  have  a  choice 
of  providers  before  they  decide 
to  sign  on  for  service,  says  Joe 
Laszlo,  an  analyst  with  Jupiter 
Media  Metrix. 

“Consumers  and  businesses 
will  likely  be  skeptical  about 
what  a  3G  service  offers  them 


Bumping  up 
wireless  bandwidth 

Features  of  Verizon’s 

Express  Network  include: 

•  Speeds  up  to  144K 
bit/sec. 

•  Wireless  enterprise 
application  hosting  in 
partnership  with 
Accenture. 

•  Cost  of  $30  per  month 
in  addition  to  the  base 
$35  cost  of  a  digital 
calling  plan. 

•  Uses  a  2235  Kyocera 
handset,  or  AirCard 
555  PC  card. 

and  how  much  it  costs  until  they 
see  more  than  one  option  avail¬ 
able,”  he  says. 

Customers  wishing  to  sub¬ 
scribe  to  Express  Network  must 
pay  $35  for  a  basic  Verizon 
Wireless  digital  calling  plan  and 
then  an  additional  $30  per 
month  to  use  any  of  the  basic 
calling  plan  minutes  on  Express 
Network. 

Verizon  officials  say  the  com¬ 
pany  expects  to  introduce  pric¬ 
ing  plans  in  the  future  for  enter¬ 
prise  customers  based  on  kilo¬ 
bytes  used. 

The  Sierra  Wireless  AirCard 
555  retails  for  about  $300  and 
the  Kyocera  handset  retails  for 
about  $80,  as  does  the  Mobile 
Office  Kit  for  the  Kyocera  hand¬ 
set. 

Verizon  Wireless:  www.verizon 
wireless.com 


Security 
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as  healthcare  organizations  and 
financial  institutions,  are  finding 
the  security  they  need  with  ASPs. 

“On  the  security  side,  the  gener¬ 
al  philosophy  is  that  ASPs  have 
more  specialized  resources  for 
looking  after  security  than  I  could 
afford  to  have  internally”  says 
Rodric  O’Connor,  vice  president 
of  technology  at  Putnam  Lovell 
Securities  in  San  Francisco. 

But  enterprise  users  should  be 
careful  to  query  ASPs  about  the 
security  services  they  offer.  ASPs 
that  cater  to  large  companies 
and  deliver  complex  applica¬ 
tions  undoubtedly  will  provide 
baseline  security  services,  such 
as  managed  firewalls,  virus  pro¬ 
tection,  intrusion  detection  and 
user  authentication.  But  smaller, 
emerging  players  may  not.  A 
study  by  1DC  last  fall  found  that 
nearly  a  quarter  of  50  ASPs  sur¬ 
veyed  failed  to  offer  basic  net¬ 
work  security. 

“They  didn’t  offer  virus  protec- 
tion.They  didn't  offer  user-authen¬ 
tication  securities,”  says  Jessica 
Goepfert.an  analyst  at  IDC.“These 
are  things  I  consider  vital  and  fun¬ 
damental  to  any  ASP  offering.  It’s 
like  renting  a  building  that  does¬ 
n’t  have  locks  on  the  doors.” 

Mark  dayman,  director  of  host¬ 
ing  at  Surebridge,  says  security  is 
becoming  increasingly  important 
—  second  only  to  performance 
concerns  —  to  customers,  and 
the  ASP  is  responding  by  provid¬ 
ing  more  security  services  on  a 


customer-by-customer  basis. 

“Everything  from  physical  se¬ 
curity,  to  the  operating  system,  to 
antivirus,  to  application  layer  se¬ 
curity,  to  network  security  and  in¬ 
trusion  detection. That’s  what  we 
offer  on  a  standard  basis,  but  it’s 
always  evolving,”  he  says.  “You 
never  know  when  a  customer  is 
going  to  come  in  and  want  some 
additional  security  layer  or  some 
added  functionality.  We ’re  always 
tweaking  our  service.” 

QCS  says  flexibility  is  a  key  to 
its  enhanced  security  services. 
QCS  partnered  with  managed 
security  service  provider  Veri- 
tect  to  offer  services  that  range 
from  intrusion  detection  to  vul¬ 
nerability  scans  to  professional 
services. 

What’s  interesting  about  the  ser¬ 
vices,  analysts  say,  is  that  they  are 
offered  in  a  tiered  manner  so 
companies  can  choose  what 
level  of  service  they  need.  Each 
service  is  integrated  with  the 
application  delivery  but  is  priced 


More  online! 


.  QCS  is  partnering  with  managed  security 
service  provider  Ventect  to  offer  services. 
.  Choosing  an  ASP. 
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in  addition  to  the  monthly  appli¬ 
cation  subscription. 

“The  idea  of  doing  it  in  terms  of 
an  add-on  makes  sense  because 
obviously  for  some  applications 
and  some  customers  it’s  not 
going  to  be  worth  spending  addi¬ 
tional  money,”  says  Laurie  Mc¬ 
Cabe,  vice  president  and  service 
director  at  technology  research 
firm  Summit  Strategies. 

However,  she  predicts  that 
over  time  the  enhanced  ser¬ 
vices  will  be  rolled  into  stan¬ 
dard  offerings  as  the  security 
bar  is  raised  in  response  to  cus¬ 
tomer  demands.  ASPs  say  cus¬ 
tomers  already  are  pushing 
them  to  be  clear  about  what 
type  of  security  is  provided. 

“Customers  are  becoming 
more  educated  about  security 
because  so  many  people  are 
doing  business  over  the  Inter¬ 
net,”  says  Chip  Gums,  vice  presi¬ 
dent  of  ASP  Agilera’s  eastern 
region  operations.“lt’s  more  of  a 
topic  during  the  sales  cycle 
today  than  it  was  a  year  ago,  and 
we  are  continuing  to  improve 
our  security  daily” 

The  bottom  line,  analysts  say,  is 
companies  should  consider 
what  applications  they  want 
delivered  from  an  ASP  and  then 
determine  the  level  of  security 
required.  A  calendar  application 
won’t  need  the  same  level  of 
security  that  payroll  software 
would,  McCabe  says. 

“You  want  the  best  security  that 
you  can  afford,”  she  says.  “Like 
everything  else,  it’s  going  to  boil 
down  to  trade-offs.”  ■ 
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VSAT:  Satellite  service  gains  attention  as  less-expensive  broadband  option. 

VSAT  services  are  finding  new  customers 


■  BY  DENISE  PAPPALARDO 

Very  Small  Aperture  Terminal  satellite  services  have 
been  a  staple  among  retail  businesses  for  more 
than  15  years,  but  now  the  technology  that  once 
served  only  vertical  markets  is  spreading  its  wings. 

VSATs  have  long  been  attractive  to  organizations  that 
needed  to  reach  hundreds  or  thousands  of  locations 
with  low-bandwidth  data  connectivity.  Businesses  in 
North  America  spent  $775  million  on  VSAT  services  in 
2000,  according  to  Comsys. 

VSAT  services  are  attracting  new  customers  for  two 
reasons:  the  dominance  of  IP  and  the  abundance  of 
bidirectional  services. VSAT  offerings  for  small  busi¬ 
nesses  are  a  relatively  new  development  and  are  also 
an  affordable  alternative. 

“The  VSAT  market  has  changed  so  much,”  says  Chris 
Baugh,  principal  analyst  with  Northern  Sky  Research. 
“Traditional  VSATs  were  in  gas  stations  and  retail 
chains  with  only  one-way  support.  IP  is  now  the  de- 
facto  network  standard,  which  has  allowed  a  lot  of 
satellite  companies  to  reduce  their  costs  and  decrease 
the  complexity  of  their  networks.” 

While  VSAT  users  have  supported  IP  traffic  over  their 
networks  for  several  years,  it  typically  has  been  one  of 
several  protocols.  IP-only  VSAT  services  are  relatively  new. 

IP  the  driving  force 

The  move  to  IP  has  been  the  result  of  customer  de¬ 
mand  and  the  ability  of  service  providers  to  lower 
costs, says  Simon  Bull,  an  analyst  with  Comsys. VSAT 
providers  are  seeing  90%  of  their  new  customers  re¬ 
questing  IP  support,  Bull  says.  When  a  service  provider 
standardizes  on  IP  they  can  reduce  their  internal  net¬ 
work  infrastructure  costs  because  they  can  buy  equip¬ 
ment  and  software  off  the  shelf. 

“By  supporting  IP  and  standardizing  certain  parts  of 
the  technology,  [service  providers]  can  deploy  two-way 
VSAT  networks  with  [customer-premises  equipment] 
that  costs  $500  to  $600,”  Baugh  says.  He  says  this  would 
be  the  floor  of  the  market  with  users  paying  about  $70 
to  $200  per  month,  per  site  for  service  for  perhaps  128K 
bit/sec  worth  of  bandwidth. 

IP-only  support  lets  service  providers  such  as  Space- 
net,  a  wholly  owned  subsidiary  of  Gilat  Satellite  Net¬ 
works,  offer  bidirectional  or  two-way  services  to  busi¬ 
nesses  with  250  or  fewer  sites. This  service,  called 
Con nexstar,  costs  $1 19  per  month  for  128K  bit/sec  up¬ 
stream  and  500K  bit/sec  downstream  with  a  one-time 
equipment  cost  of  $1,000. 

Hughes  Network  Services,  the  leading  provider  of  VSAT 
sendees  in  North  America  (see  graphic),  offers  small- 
business  users  Directway,  a  VSAT  Internet  access  service. 
Starband  and  Tacyon  also  sell  VSAT  Internet  access  ser¬ 
vices  to  individual  users.These  offerings  let  a  greater 
variety  of  businesses, such  as  real  estate  agencies  and 
veterinarian  offices,  use  VSAT  services,  Bull  says. 

In  the  past,  most  VSAT  service  providers  were  interested 
only  in  deployments  that  reached  thousands  of  sites, 
but  there  has  been  a  change  of  philosophy  within  the 
industry.  While  several  VSAT  services  for  single  sites  are 
available,  not  all  providers  are  sold  on  the  concept. 

Traditional  VSAT  networks  are  built  based  on  the 
amount  of  bandwidth  a  company  needs  and  the  num¬ 


ber  of  sites  that  will  share  that  bandwidth,  says  Mike 
Massey,  an  analyst  with  Pioneer  Consulting.  Selling  indi¬ 
vidual  Internet  access  over  the  same  satellites  to  thou¬ 
sands  of  customers  is  presenting  some  problems. 

“The  downside  is  now  you’re  trying  to  develop  a  ser¬ 
vice  offering  based  on  an  anticipated  profile  of  a  given 
customer,”  Massey  says. “You’re  not  designing  a  whole 
network  based  on  one  company’s  usage  patterns.” 

So  while  a  company  such  as  Hughes  promotes  that  it 
has  more  than  100,000  customers  using  its  DirectWay 
service,  some  users  are  dealing  with  frustrating  band¬ 
width  constraints,  he  says.  Providers  of  these  services 
are  going  through  a  lot  of  growing  pains  trying  to  fig¬ 
ure  out  how  to  offer  individual  access,  yet  allocating 
enough  bandwidth  so  users  get  high-quality  service, 


VSAT  service  provider  market 

A  recent  report  shows  that  Hughes  Network 
Systems  and  Spacenet  provide  the  majority 
of  VSAT  services  in  North  America  based  on 
the  number  of  terminals  shipped. 
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while  keeping  costs  in  check,  he  says. 

While  VSAT  Internet  access  options  open  up  broad¬ 
band  services  to  users  in  areas  where  DSL  or  cable 
modem  services  are  not  found  easily,  the  industry  is 
still  working  out  kinks  with  this  offering.  However,  ana¬ 
lysts  say  it’s  just  a  matter  of  time  before  service  pro¬ 
viders  fine-tune  bandwidth  allocations  to  make  individ¬ 
ual  VSAT  offerings  a  success. 

The  real  benefit  with  these  offerings  is  you  can  get 
VSAT  anywhere,  Bull  says,  unlike  DSL  and  cable  modem 
services.  And  the  next  high-speed  network  option  for 
users  would  be  a  fractional  T-l  line  or  a  frame  relay 
connection,  both  of  which  cost  hundreds  or  even  a 
thousand  dollars  per  month  more  than  a  VSAT,  DSL  or 
cable  modem  service. 

The  geographical  reach  of  VSAT  technology  was  a 
prime  reason  why  Bob  Evans  Farms  deployed  a  481- 
site  network  about  16  months  ago. The  national  restau¬ 
rant  chain  teamed  with  Spacenet  to  link  its  retail  stores 
and  corporate  headquarters  to  an  always-on  IP  VSAT 
service,  says  Larry  Beckwith,  vice  president  of  IS  in  Co¬ 
lumbus,  Ohio.  And  the  network  was  up  and  running  in 
five  weeks,  he  says. 

While  Beckwith  looked  into  frame  relay,  DSL  and 
ISDN  service  options,  he  chose  a  VSAT  network  be¬ 
cause  it  was  the  only  technology  that  could  reach  all 
locations  and  was  the  most  cost-effective,  he  says. 


“Initially  we  were  looking  to  reduce  the  amount  of 
time  credit  card  authorization  took  at  our  stores,” 
Beckwith  says.“We  reduced  that  from  15  seconds 
down  to  3  seconds.” 

Since  replacing  Bob  Evan’s  dial-up  network,  Beckwith 
says  he  has  added  e-mail,  has  streamlined  the  company’s 
inventory  process  by  creating  a  browser-based  invoice 
application,  and  will  soon  add  human  resource  applica¬ 
tions  to  his  VSAT  network. 

Another  recent  development  that’s  bringing  VSATs 
into  more  businesses  is  that  providers  have  struck 
deals  with  terrestrial  carriers.  Hughes  signed  a  deal 
that  lets  users  buy  Hughes  VSAT  services  through 
WorldCom.  Baugh  says  users  likely  will  see  similar 
deals  not  only  with  terrestrial  service  providers,  but 
also  with  hardware  vendors. 

VSATs  are  considered  an  add-on  service  rather  than  a 
full-fledged  alternative  to  terrestrial  networks,  he  says. 
VSATs  are  attractive  for  businesses  that  want  to  sup¬ 
port  specific  content  such  as  corporate  training  and 
e-learning  to  multiple  locations,  but  don’t  want  to  add 
more  bandwidth  throughout  their  terrestrial  networks 
to  support  such  applications,  Baugh  says. 

SLAs  more  common 

Service-level  agreements  also  are  becoming  more 
common  as  VSAT  service  providers  realize  enterprise 
requirements.  Users  should  expect  at  least  two  service 
guarantees:  one  for  throughput  and  one  for  uptime, 
Baugh  says.  Because  harsh  weather  will  impact  satel¬ 
lite  services,  Baugh  says  users  have  to  be  prepared  for 
some  downtime.  Realistically,  most  VSAT  providers  can 
guarantee  99.9%  availability,  but  users  should  only  put 
applications  over  a  VSAT  network  that  could  tolerate 
eight  to  10  hours  per  year  of  downtime. 

While  developments  in  VSAT  technology  will  continue, 
the  traditional  VSAT  network  that’s  based  on  a  star  topol¬ 
ogy  is  still  a  solid  choice  for  many  business  users, 
Massey  says.“Depending  on  the  type  of  network,  a  VSAT 
setup  could  be  cheaper  per  location  than  a  voice  line  in 
some  cases,”  he  says. 

In  the  case  of  a  chain  of  retail  stores  that  use  their 
VSAT  networks  for  credit  card  authorizations,  not  much 
bandwidth  is  needed.  A  group  of  500  stores  could  share 
a  128K  bit/sec  satellite  channel  and  not  experience 
any  delays  because  of  the  small  amount  of  traffic 
that’s  being  sent  over  the  network,  even  though  it’s  reg¬ 
ularly  used. 

A  company  with  4,000  locations  might  pay  about  $60 
per  month,  per  VSAT  site.  Businesses  with  a  few  hun¬ 
dred  sites  probably  will  pay  about  $100  per  month,  per 
site  for  the  same  amount  of  bandwidth. 

“Trying  to  build  an  alternative  ISDN  network  or  a  56K 
bit/sec  frame  relay  network  is  much  more  expensive,” 
Massey  says.  ■ 


More  online! 

Hughes  Network  Services  predicts  new  satellite 
technology  to  deliver  30M  bit  sec  download  and 
500K  bit/sec  upload  speeds  by  2003. 
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LOOK  FOR 
THE  DLTtape  LOGO 


For  more  than  a  decade,  DLTtape"  technology 
has  been  known  for  its  unparalleled  reliability 
in  data  protection  and  retrieval.  That’s  why 
you  should  always  look  for  the  DLTtape  logo 
when  buying  DLTtape 
products.  This 
ensures  that 
your  company’s  J 
mission-critical 
data  is  trusted  to  a 
quality  media  that  has  met  the 
highest  standards  for  reliability, 
compatibility  and  performance.  In  fact, 
DLTtape  cartridges  must  pass  a  rigorous 
process  to  become  fully  qualified  and 
display  the  DLTtape  logo.  This  guarantees 


you’re  getting  the  de  facto  standard  for  data 
backup  and  retrieval.  Products  that  do  not 
have  the  DLTtape  logo  have  not  met  these 
rigorous  qualification  standards. 

So,  be 
sure  to  use 
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cartridges 
that  carry  the 
DLTtape  logo. 
It  gives  you 


the  confidence  in  knowing  you’ve  purchased 
the  ultra-reliable  backup  solution  that’s 
chosen  5:1  by  IS/IT  managers.  To  find  out 
how  the  DLTtape  logo  has  become  the 
ultimate  symbol  of  quality  and  reliability, 
go  to  www.dlttape.com/qualified. 
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Nortel  expands  metro  Ethernet  portfolio 

New  boxes,  enhancements  to  OPTera  3500  designed  to  spur  VPN  service  provisioning. 


Nortel  introduces  MPLS  VPN  architecture 

New  gear  combines  multisite  traffic  onto  a  single  path. 
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Customer  traffic  from  VPNs  A  and  B  is  separated 
in  the  OPTera  Metro  1200  using  MPLS  labels. 
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The  OM  8000  sets  up  a  single  MPLS  LSP 
to  carry  traffic  from  both  VPNs.This 
Nortel-specific  technique  reduces  the 
number  of  LSPs  that  are  needed. 


Through  autodiscovery  ofVPN- 
to-LSP  mappings,  the  OM  1200 
destination  node  is  able  to  for¬ 
ward  traffic  to  the  appropriate 
destination. 


■  BY  TERRI  GIMPELSON 

OTTAWA  —  Nortel  last  week  updated  its 
metropolitan  Ethernet  line  with  two  de¬ 
vices  and  enhancements  to  an  existing 
platform. 

The  new  products  are  the  OPTera  Metro 
1200  Ethernet  Services  Module  (ESM)  and 
the  OPTera  Metro  8000,  which  is  designed 


■  Lucent  last  week  announced  it  is 
shipping  its  next-generation  optical 
transport  system  and  switch,  the 
LambdaUnite  MultiService 
Switch.  The  product  can  connect 
cities,  campuses  and  corporate  net¬ 
works  to  the  long-haul  public  network, 
Lucent  says.  It  combines  a  SONET/ 
SDH  optical  transport  system  with 
switching  capacity  of  up  to  640G 
bit/sec  and  supports  interfaces  rang¬ 
ing  from  155M  bit/sec  to  40G  bit/sec. 
Lucent  says  two  separate  MSS  sys¬ 
tems  can  fit  into  a  single  rack,  taking 
the  place  of  multiplexers  and  cross- 
connect  systems.  Deutsche  Telekom 
will  start  testing  MSS  this  month.  The 
company  plans  to  use  the  box  to  sup¬ 
port  and  deploy  broadband  services  in 
its  global  network,  www.lucent.com 

■  ATM  and  frame  relay  switch  start¬ 
up  WaveSmith  Networks  has  ap 

pointed  two  new  executives.  Brian 
Fitzgerald  has  been  named  execu¬ 
tive  vice  president  of  worldwide  sales, 
and  Tom  Amato  has  been  named 
CFO.  Fitzgerald  was  vice  president  of 
worldwide  sales  at  Convergent  Net¬ 
works,  responsible  for  building  the 
company’s  sales  force  and  securing 
its  first  customers.  Fitzgerald  also 
held  positions  at  Lucent,  Agile  Net¬ 
works  and  Racal  Data  Group.  Amato 
was  vice  president  and  CFO  for  Intel's 
Dialogic  division.  He  also  held  execu¬ 
tive  positions  at  Symbol  Technologies, 
Amcast  Industrial  and  Rockwell 
International,  www.wavesmith 
networks.com 


for  provisioning  Ethernet  VPNs. 

The  1200  sits  at  the  metropolitan  edge  or 
customer  premises  and  serves  as  an  Ether¬ 
net  aggregation  device.  It  supports  one  or 
two  Gigabit  Ethernet  uplinks  to  the  service 
provider  and  12  10/100M  bit/sec  Ethernet 
downlinks  to  the  user. 

Nortel  says  the  box  can  isolate  customer 
traffic  securely  to  ensure  data  privacy  a  fea¬ 
ture  that  replaces  a  similar  function  pro¬ 
vided  by  virtual  LANs  (VLAN).  Nortel  says 
the  1200  eliminates  the  need  to  configure 
dedicated  VLANs  and  manage  large  num¬ 
bers  of  VLAN  tags  by  creating  VPNs  out  of 
a  single  Multi-protocol  Label  Switching 
(MPLS)  label-switched  path  (LSP).  That’s 
where  the  OPTera  Metro  8000  and  en¬ 
hancements  to  the  existing  OPTera  Metro 
3500  come  in.  Both  boxes  establish  this  LSP 
at  the  central  office  for  the  1200s. 

The  8000  is  a  Layer  2  MPLS  metropolitan 
core  switch  designed  for  traffic  engineer¬ 
ing.  It  comes  in  three-,  six-  or  10-slot  chassis 
that  house  four-port  Gigabit  Ethernet  mod¬ 
ules,  with  a  future  upgrade  to  eight  ports. 

MPLS  features  on  the  8000  are  based  on 
the  lETF’s  proposed  Draft  Martini  standard, 
which  specifies  how  VPNs  can  be  set  up  at 
Layer  2.  However,  Nortel  adds  its  own  exten¬ 
sions  to  Draft  Martini. 

The  company  says  that  in  a  meshed 
MPLS  VPN,  Draft  Martini  requires  the 
provisioning  of  all  new  LSPs  with  the 


■  BY  JIM  DUFFY 

SANTA  CLARA  —  Nokia  is  pitching  a 
broadband  access  platform  the  company 
claims  will  let  service  providers  begin  the 
transition  from  their  current  multiple 
access  networks  to  an  IP  infrastructure. 

The  Nokia  D500  is  a  DSL  access  multi¬ 
plexer  (DSLAM)  that  lets  service  pro¬ 
viders  provisioning  access  services  over 
ATM  introduce  IP-based  voice  and  multi- 
media  services.Such  services  will  include 
video  on  demand;  pay-per-view;  interac¬ 
tive  gaming;  videoconferencing;  real-time 
broadcast  and  interactive  TV;  and  stream¬ 
ing  audio. 

However,  these  services  are  all  “futures” 
to  be  rolled  out  on  the  D500  over  an 


addition  of  just  one  new  site.  This  pre¬ 
sents  scalability  issues  in  that  the  num¬ 
ber  of  LSPs  grows  exponentially  as  new 
VPN  sites  are  added,  Nortel  says. 

What  Nortel  proposes  is  a  single  LSP 
that  is  given  specific  VPN  pathways  at 
the  customer  premises.  The  company 
says  it  splits  the  provider  edge  into  two 


indefinite  time.  At  first,  the  D500  will  sup¬ 
port  high-speed  Internet  access,  voice 
over  DSL,  IP  VPNs,  LAN  interconnection 
and  video  streaming. 

The  D500  also  enables  incumbent  local 
exchange  carriers  (ILEC),  regional  Bell 
operating  companies,  and  post,  telegraph 
and  telephone  administrations  to  evolve 
existing  network  infrastructures  to  IP  to 
support  new  services  at  a  lower  cost  than 
with  ATM,  Nokia  says. 

The  D500  features  a  160G  bit/sec  back¬ 
plane,  or  4G  bit/sec  per  slot  of  capacity.  It 
supports  asymmetric  DSL,  single-pair 
high-speed  DSL  and  very-high  bit  rate 
DSL  services. 

It  also  supports  OC-3,  OC-12,  100Base-T 
Ethernet  and  Gigabit  Ethernet  interfaces, 


pieces,  creating  what  it  has  deemed  a 
“Logical  Provider  Edge”  comprised  of 
two  boxes  that  provision  LSPs  for  the 
MPLS  VPN  pathways  created  at  the  cus¬ 
tomer  site. 

The  boxes  perform  MPLS  label  stacking 
to  aggregate  VPN  pathways  onto  LSPs. 

See  Nortel,  page  42 


in  addition  to  IP  routing  and  plain  old 
telephone  services. 

The  platform  provides  912  DSL  ports  per 
shelf  of  density  and  up  to  2,736  ports  per 
seven-foot  rack.  This  kind  of  density  in  a 
remote  site  application  lets  more  than  250 
users  connected  to  a  single  cabinet  or 
basement  installation  receive  up  to  6M 
bit/sec  video  channels  per  user,  Nokia 
says.  Other  DSLAMs  are  half  as  dense, 
according  to  the  company 
Analysts  say  Nokia  is  now  the  market 
leader  in  DSLAM  density 
“The  D500  platform  has  leapfrogged  the 
competition  and  now  offers  the  highest- 
density  DSLAM  on  the  market,  paving  the 
way  for  Nokia  to  penetrate  the  revenue- 

See  Nokia,  page  42 


Nokia  unveils  dense  IP/ATM  DSLAM 

D500  initiates  migration  from  legacy  service  infrastructures. 
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Metro  is  Cisco’s  core  IP  market  now 

Company  dismisses  ‘hype’  on  next-generation  backbones,  says  edge  is  where  the  money  is. 


■  BY  JIM  DUFFY 

SAN  JOSE  —  While  the  indus¬ 
try  anticipates  Juniper  Net¬ 
works’  next-generation  core  plat¬ 
form,  Cisco  says  the  Internet 
router  market  is  elsewhere  at  the 
moment. 

The  company  is  focusing  on  the 
metropolitan  edge,  where  it  sees 
an  immediate  customer  need 
and  the  shortest-term  opportunity 
for  Cisco.  All  the  talk  about  40G 
bit/sec/slot  capacity  and  multi¬ 
chassis  scale  into  terabit  perfor¬ 
mance  —  supposed  features  of 
Junipers  upcoming  core  plat¬ 
form  —  is  just  hype  to  Cisco. 

“In  2000  and  2001,  there  was  a 
lot  of  focus  on  10G  bit/sec  back¬ 
bones”  says  Robert  Redford,  vice 
president  of  marketing  in  Ciscos 
Internet  Routing  group.  “Now  the 
shift  is  more  to  the  edge  and 
metro,  and  turning  new  revenue 
services  on.” 

Redford  dodges  questions 
about  Cisco’s  plans  for  next-gen¬ 
eration  IP  cores  —  as  in,  what’s 
the  scoop  on  40G  bit/sec  and  ter¬ 
abit  scale  from  Cisco? 

“Traffic  has  slowed,”  Redford 
says.The  next  big  router  is  not  as 
much  of  an  issue  anymore.” 

With  regard  to  40G  bit/sec/slot 
capabilities,  Redford  says  it’s  less 
expensive  for  10G  bit/sec  cus¬ 
tomers  to  just  buy  a  couple  of 
OC-192s  than  30  more  gigabits. 


Nortel 

continued  from  page  41 

VPN  pathway-to-LSP  assign¬ 
ment  is  handled  via  the  MPLS 
label-distribution  protocol. 

This  technique  eliminates  the 
need  to  provision  an  exponen¬ 
tially  growing  number  of  links  in 
a  virtual-mesh  VPN  with  a  single 
link  between  the  provider  edge 
and  the  provider  core,  Nortel 
says.  Nortel  has  proposed  this 
method  to  the  IETF 

Nortel’s  technique  is  an  impor¬ 
tant  industry  option,  says  Marian 
Stasney,  senior  analyst  at  The 
Yankee  Group.  But,  “I  caution 
them  to  keep  everything  stan- 
dards-based,”she  says. 

Another  enhancement  to  the 
OPTera  3500  is  the  addition  of 
an  Ethernet  user-to-network 
interface  to  support  provision¬ 
ing  to  end  points  configured 
with  the  OPTera  1200  The  com- 


Riding  the  metro 

The  10720  router  is  Cisco’s  key 
metro  IP  platform  for: 


Provisioning  Ethernet  services 
to  multitenant  units. 

Constructing  Dynamic  Packet 
Transport  rings  around  cities. 

Demonstrating  resiliency  of  IP 
services. 

Enabling  multicast  services. 


Does  this  mean  Cisco  will  unveil 
dual-port  OC-192s  for  the  12000 
Internet  Router  line? 

“There’s  always  a  desire  for 
more  capacity  and  incremental 
innovation  for  that  to  happen,” 
Redford  says.  “You’ll  see  higher 
and  higher  density  per  slot,  but 
power  and  heat  are  [limiting] 
issues.” 

And  what  happened  to  the  ter¬ 
abit  scalability  story  Cisco  was 
eager  to  tell  two  years  ago  when  it 
unveiled  the  12016  router?  At  that 


pany  also  enhanced  its  Pre¬ 
side  Ethernet  Provisioning  soft¬ 
ware  to  provide  automated 
provisioning  of  end-to-end 
services. 

In  addition  to  the  1200,  Nortel 
says  the  3500  and  the  8000  can 
be  used  at  the  customer  pre¬ 
mises  edge,  depending  on  the 
size  and  location  of  the  network. 
Stasney  says  the  different  archi¬ 
tectures  of  the  individual  boxes 
may  preclude  line  card  compat¬ 
ibility  and  sparing,  however. 

The  1200  will  be  available  in 
March  for  $25,000  to  $30,000,  de¬ 
pending  on  the  types  of  inter¬ 
faces.  The  8000  will  sell  for 
$300,000  fully  populated,  or 
around  $6,000  per  port.  It  will  be 
available  in  the  second  quarter. 

The  enhanced  version  of  Pre¬ 
side  Ethernet  Provisioning  will 
be  available  in  June. 

Nortel:  www.nortelnetworks 
.com 


time,  Cisco  said  the 
12016  could  achieve 
more  than  5T  bit/sec  of 
capacity  by  connecting 
multiple  chassis  to  a  sep¬ 
arate  256x256  switching 
matrix  (www.nwfusion 
.com,  DocFinder:  7929). 

Since  then,  Cisco’s 
been  conspicuously 
silent  on  terabit  scalabil¬ 
ity  while  rumors  have 
swirled  that  the  com¬ 
pany  has  had  to  rework 
its  terabit  plans  more 
than  once.  Then  again, 
the  market  for  terabit- 
scale  routers  hasn’t  ex¬ 
actly  scorched  the  earth. 

“There’s  been  abso¬ 
lutely  no  traction  in  ter¬ 
abit,”  Redford  says. 
“Purchase  behavior  has 
been  different  from  the 
hype.” 

As  a  result,  Cisco’s  terabit  plans 
are  still  evolving,  Redford  says.  He 
says  Cisco’s  made  some  single¬ 
chassis  switch  fabric  scalability 
enhancements  —  most  recently 
with  the  320G  bit/sec  fabric  for 
the  12016. 

“We’ll  put  it  in  the  chassis  first 
and  go  to  multiple  chassis  to 
scale  if  we  have  to,”  Redford  says. 

But  external  switching  fabrics 
to  interconnect  multiple  chassis 
are  costly  because  they  consume 
ports,  slots  and  rack  space,  he 
says.  And  as  demand  for  terabit 
scale  has  lagged,  Cisco  found 
time  to  revisit  its  strategy 

“Are  we  committed  to  external 
fabrics?  Yes,”  Redford  says.“Do  we 


need  to  get  there  this  year?  No.” 

This  year,  carriers  are  demand¬ 
ing  10G  bit/sec  capabilities  in 
smaller  form  factors  for  the  met¬ 
ropolitan  area  and  edge,  Red¬ 
ford  says.  They’re  also  looking 
for  a  six-month  return  on  invest¬ 
ment,  he  says. 

“The  bulk  of  the  market  will  be 
in  the  middle  of  the  market  [be¬ 
tween  edge  and  core] ,  which  is 
not  as  sexyf  Redford  adds. 

Cisco  demonstrated  the  ability 
for  service  providers  to  provi¬ 
sion  Ethernet  to  multitenant 
units  using  its  four-slot,  80G 
bit/sec  12404  router,  10720 
router  and  Catalyst  2900  XL 
switches.  The  10720,  announced 
in  October,  is  Cisco’s  first  “pur¬ 
pose  built”  IP  router  for  the  met¬ 
ropolitan  market. 

The  10720  is  a  2U-high  (3.5 
inches)  device  that  features  24 
10/100M  bit/sec  Ethernet  ports 
and  a  2.5G  bit/sec  uplink  to  a 
dual  counter-rotating  ring.  The 
10720  aggregates  subscriber 
Ethernets  from  the  2900  XL 
switches  and  connects  them  to  a 
Cisco  Dynamic  Packet  Transport 
(DPT)  metropolitan  fiber  ring. 

DPT  is  designed  to  optimize 
transport  of  packet  data  and 
Ethernet  over  a  TDM  infrastruc¬ 
ture  such  as  SONET,  with  the 
same  50  msec  resiliency  as 
SONET.  DPT  is  also  a  prestandard 
version  of  IEEE  802.17  Resilient 
Packet  Ring,  which  is  15  months 
from  completion. 

DPT  uses  Cisco’s  Spatial  Reuse 
Protocol  to  improve  bandwidth 
utilization  on  the  ring.  Spatial 


Reuse  Protocol  enables  use  of 
both  the  active  and  the  protect 
parts  of  a  SONET  ring,  and  per¬ 
forms  IP  packet-level  multiplex¬ 
ing  to  use  all  available  band- 
width.This  effectively  provides  5G 
bit/sec  throughput  on  a  2.5G 
bit/sec  OC-48  ring,  Cisco  says. 

DPT  also  uses  SONET  framing, 
which  lets  service  providers  run 
OC-12  DPT  channels  on  an  OC-48 
SONET  ring,  Cisco  says. 

Cisco  has  sold  14,500  OC-12 
and  0C48  DPT  ports  to  190  cus¬ 
tomers.  OC-192  DPT  is  a  planned 
enhancement. 

Analysts  see  the  10720  as  more 
of  a  strategic  platform  for  Cisco 
rather  than  a  tactical  generator  of 
quick  revenue.  Current  Analysis 
says  10720  sales  will  be  few,  lim¬ 
ited  to  a  smattering  of  Tier  3  IP¬ 
centric  service  providers. 

But  it’s  strategically  important  in 
that  Cisco  needs  to  demonstrate 
that  its  core  competence  —  IP  — 
is  resilient  enough  for  carrier- 
class  service  provisioning. 

“The  10720  is  a  sign  of  Cisco’s 
future  direction,”  Current  Analysis 
said  in  a  recent  report.  “Cisco 
needs  to  drive  the  market  toward 
as  many  IP-based  solutions  as 
possible.  The  money  for  Cisco’s 
customers  will  increasingly  come 
from  differentiated  services  re¬ 
quiring  high  capacityCisco  needs 
to  address  the  resiliency  and  dif¬ 
ferentiated  characteristics  of 
future  carrier  service  revenue 
opportunities  with  its  IP  portfolio 
better  if  the  company  is  to  maxi¬ 
mize  its  addressable  market  for 
the  future."  ■ 


Nokia 

continued  from  page  41 

rich  RBOC/ILEC/PTT  accounts  and  become  a  top 
DSLAM  vendor  with  double-digit  market  share,”  Eric 
Keith,  an  analyst  at  Current  Analysis, said  in  a  recent 
report.  “The  market-leading  DSL  sub¬ 
scriber  port  density/scalability  of  the 
D500  platform  —  as  well  as  its  ATM-to- 
1P  migration  proposition  —  is  quite 
compelling  and  poses  a  direct, serious 
threat  to  the  established  DSLAM  mar¬ 
ket  leaders.” 

Keith  notes  caveats,  however.  Nokia 
will  contend  with  Tier  1  DSLAM  equip¬ 
ment  vendors  Alcatel,  Lucent,  Cisco, 
and  Siemens,  all  of  which  can  assert 
more  comprehensive  product  port¬ 
folios  than  Nokia. 

Also,  the  D500  does  not  support 
frame  relay  service  delivery  which  lim¬ 


its  its  market  penetration  potential. 

“Many  service  providers  —  such  as  those  serving 
the  banking  industry  —  utilize  frame  relay  to  deliver 
secure  IP  services’  that  are  transparent  to  the  end 
user,"  Keith  says. 

The  D500  supports  the  IP  Group  Multicast 
Protocol  for  multicast  services, 
which  are  key  for  IP-based  video 
and  TV  applications.  It  also  sup¬ 
ports  virtual  LAN  configurations, 
DiffSerythe  Resource  Reservation 
Protocol  and  Multi-protocol  Label 
Switching  for  IP  quality  of  service, 
and  dynamic  bandwidth  alloca¬ 
tion  and  control  for  bandwidth- 
on-demand  applications  such  as 
video. 

The  D500  will  be  available  in  the 
second  quarter.  Pricing  was  not  dis¬ 
closed. 

Nokia:  www.nokia.com 


More  online! 

Nokia  acquires  Amber  Networks  and 
its  technology  for  developing 
fault-tolerant  edge  routers. 
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Covalent  Enterprise  Ready  Server,  powered  by  Apache  2.0 


First  we  helped  create 


Centralized  browser-based  management  of  hundreds  of  servers 


server. 


Enterprise  grade  Web  server  security 


Built  on  Apache  for  proven  reliability 


for  your  enterprise. 


Visit  www.covalent.net/apache20  and  find  out  how  to  save  30% 
on  your  Web  infrastructure  today.  Or  call  us  at  800/444-1935. 
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^^^ecent  events  have 

catapulted  disaster 

recovery  and  business 
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top-of-mind  status  among 

Network  IT  Executives. 

If  insuring  the  safety  of 

your  network  ranks  high 

■ 

on  your  priority  list,  then 

the  contents  of  this 

SPECIAL  REPORT  should 

be  of  specific  interest 

to  you. 

Network  World  Fusion  offers  a  SPECIAL  REPORT: 

Disaster  Recovery  and  Business  Continuity 

-  Insuring  the  Safety  of  Your  Network  - 

For  a  limited  time,  you  can  get  a  copy  of  this  SPECIAL  REPORT,  free.  Just  sign  up  for 
any  of  Network  World's  over  40  technology  specific  e-mail  newsletters  and  we  will 

send  you  the  Network  World  Fusion  SPECIAL  REPORT:  Disaster  Recovery  and  Business 
Continuity  -  Insuring  the  Safety  of  Your  Network  absolutely  free.  Remember,  you  can 
only  gain  access  to  this  SPECIAL  REPORT  by  signing  up  for  a  Network  World  Fusion 
newsletter.  Sign  up  today  at  http://www.nwwsubscribe.com/foc334 


Exclusive  to,  and  produced 
by  Network  World,  this 
SPECIAL  REPORT  covers 
the  technologies,  critical 
thinking  and  products  that 
provide  for  guaranteed  data 
backup  and  swift  recovery 
of  corporate  networks. 
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Syndication  enhances  Web  services 


■  BY  EILON  RESHEF 

Web  services  has  emerged  as  a  general 
term  that  refers  to  offering  applications  to 
many  business  partners  and  integrating 
these  applications  into  their  Web  sites 
quickly  and  seamlessly.  Application  syndi¬ 
cation  is  a  central  technology  for  accom¬ 
plishing  this  goal. 

Application  syndication  lets  compa¬ 
nies  package  any  Web  application  — 
complete  with  all  its  features  —  and 
effectively  integrate  it  into  multiple  part¬ 
ner  Web  sites.  Just  as  production  studios 
syndicate  TV  programs  to  broadcast  net¬ 
works  and  local  stations,  online  applica¬ 
tion  syndication  is  the  reuse  of  assets  in 
multiple  contexts  to  generate  more 
revenue. 

Interactive  Web  services  simplify 

Application  syndication  lets  application 
providers  package  any  Web  application  as 
an  interactive  Web  service. To  package  an 
application  for  syndication,  the  applica¬ 
tion  provider  places  auxiliary  HTML 
attributes  in  its  Web  application  pages  to 
identify  the  parts  of  the  pages  that  are  to 
be  shared. 

Then,  the  provider  exposes  the  Web 
service  to  its  partners.  The  provider  can 
publish  the  service  in  a  public  registry, 
such  as  the  Universal,  Description  Dis¬ 
covery  and  Integration  or  private  direc¬ 
tory,  or  deliver  it  directly  to  business 
partners. 

To  incorporate  interactive  Web  ser¬ 
vices,  business  partners  don’t  need  to 
install  any  new  software.  They  create 
HTML  container  pages  and  insert  an 
HTML  line  in  the  page  location  where 


the  Web  service  is  to  appear.  When  the 
end  user  accesses  the  business  partner’s 
site,  the  Web  service  is  integrated  —  in 
real  time  —  from  the  live  provider  site. 

The  central  element  of  this  technology 
is  the  syndication  server.  The  syndication 
server  is  located  at  the  application 
provider  facility  and  serves  the  request  for 
the  interactive  Web  service. 

First,  end  users  reach  the  partner  site 
and  receive  the  container  page  via 
HTTP  The  client  browser  issues  an  HTTP 


request  to  the  syndication  server, 
requesting  the  Web  service. The  syndica¬ 
tion  server  issues  a  request  to  the 
provider  application  for  an  HTML  page. 
Using  the  auxiliary  tags  to  identify  the 
Web  service  within  the  provider  appli¬ 
cation,  the  server  processes  the  page 
and  returns  it  to  the  client.  As  users 
interact  with  the  application,  they 
remain  in  the  partner  site  and  dynami¬ 
cally  receive  new  pages  from  the 
provider  Web  service. 


During  syndication,  the  server  process¬ 
es  the  HTML  pages  to  fit  the  container 
environment,  transparently  handling 
such  issues  as  presentation,  navigation, 
interaction  and  personalization.  It  also 
facilitates  click-stream  reporting  by  both 
parties,  and  can  help  the  applications 
share  data  at  the  points  that  require 
functional  integration. 

Syndication  helps  companies  drive 
e-business  growth 

Several  benefits  flow  from  this  syndi¬ 
cation  model.  First,  it  supplies  a  system¬ 
atic  architecture  for  sharing  complete 
applications  with  partners,  letting  busi¬ 
nesses  leverage  their  existing  technol¬ 
ogy  investments. 

Second,  the  model  is  easy  to  imple¬ 
ment  and  integrate  into  partner  sites. 
Partners  are  not  required  to  redevelop 
or  reengineer  the  user  interface  —  an 
effort  that  can  easily  become  a  barrier 
to  establishing  an  online  business 
relationship. 

Application  syndication  and  interac¬ 
tive  Web  services  are  becoming  a  stan¬ 
dard  for  encapsulating  business  logic 
and  sharing  it  with  business  partners. 

They  let  businesses  leverage  their 
existing  technology  investments  and 
equip  business  partners  with  proven 
applications  and  tools.  They  offer  an 
innovative  model  that  brings  businesses 
significantly  closer  to  fully  realizing  the 
full  potential  of  the  Web  and  keeping 
pace  with  the  Internet’s  evolution. 

Reshef  is  vice  president  of  products  for 
WebCollage.  He  can  be  reached  at 
eilon.  reshef@webcollage.  com. 


Syndication  server 


A  syndication  server  provides  Web  services  to  multiple  online  partners. 
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The  end  user  also  issues  an 
HTTP  request  to  the  syndi¬ 
cation  server,  requesting  the 
Web  service. 


Partner  site 


Container  page 
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The  syndication  server  issues  a 
request  to  the  provider  application 
for  an  HTML  page. 


Using  auxiliary  tags  to  identify  the  Web  service 
within  the  provider  application,  the  server  sends 
the  application  to  the  end  user. 


Application 

provider 


Dr.  Internet 


By  Steve  Blass 


We  recently  changed  our  network  from  a  standard 
workgroup  with  a  server  to  a  Windows  2000 
domain,  making  the  server  a  primary  domain  con¬ 
troller.  The  clients  need  to  use  a  modem  attached 
to  the  server  to  dial  out  to  a  partner  network.  The 
modem  sharing  broke  during  the  upgrade.  On  each 
workstation  we  added  new  accounts  for  the  local 
user  to  log  on  to  the  domain.  When  local  users  log 
on  to  the  domain  and  use  the  client  software  for 
modem  sharing  and  tests  for  the  modem,  it  works. 


But  when  they  actually  try  to  use  it  the  system 
fails.  It  never  works  the  first  time,  but  it  might 
work  after  three  or  four  attempts,  but  only  if  the 
domain  user  has  administrative  rights  on  the 
workstation.  Otherwise,  it  says  it  can't  find  the 
modem.  If  we  log  off  and  back  on  as  a  local  user 
account  everything  works  again.  How  can  we 
make  it  work  for  domain  users? 

Add  a  new  "dial-up  to  private  network”  connection 


through  the  “network  and  dial-up  connections" 
menu  in  the  server’s  control  panel.  Select  "for  all 
users”  when  prompted  to  specify  who  can  use  the 
connection.  Domain  clients  then  should  be  able  to 
use  the  connection.  You  also  may  need  to  reinstall 
the  application  that’s  breaking  from  the  server. 

Blass  is  a  network  architect  at  Change® 
Work  in  Houston.  He  can  be  reached  at 
dr.internet@changeatwork.com. 
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GLARHEAD 
INSIDE  THE 
NETWORK 
MACHINE 

Mark 

Gibbs 


“Yes  raster  is  faster,  but  raster  is  vaster, 
and  vector  just  seems  more  corrected 

—  Professor  Dana  Tomlin,  University  of 
Pennsylvania  (www.nwfusion.com,  Doc- 
Finder:  8028) 

Some  weeks  ago  . . .  wait  a  minute,  it 
was  last  June!  Doesn’t  time  fly  when 
you're  enjoying  yourself?  Anyway,  way 
back  then  we  spent  a  few  columns  dis¬ 
cussing  a  new  graphics  technology 
called  Scalable  Vector  Graphics,  or  SVG 
(DocFinder:  8029). 

Well,  SVG  has  matured  to  become  a 
World  Wide  Web  Consortium  Recom¬ 
mendation  (see  www.w3.org/TR/SVG/), 
and  members  of  the  SVG  community  are 
forging  ahead  with  dreams  of  world  dom¬ 
ination  dancing  in  their  heads. 

A  good  example  of  this  drive  is  an  article 
by  Antoine  Quint  titled  “Digging  Ani- 
mation”on  XML.com  (DocFinder: 8030), in 
which  Quint  discusses  how  a  Flash  anima¬ 
tion  can  be  migrated  to  SVG  —  something 


SVG  update 

that  should  gladden  the  hearts  of  all  who 
would  prefer  to  see  ubiquitous  Flash  Web 
presentations  disappear  without  a  trace. 
(Frankly,  we  don’t  see  the  problem  with 
Rash.  If  you  are  one  of  these  naysayers, 
please  enlighten  us.)  Hmmm,  interesting 
thought:  If  SVG  really  becomes  dominant, 
could  we  see  Macromedia  dumping  its 
proprietary  Flash  in  favor  of  the  open-stan¬ 
dard  SVG? 

Something  we  have  noted  about  SVG  is 
that  cartographers  in  particular  seem  to  be 
getting  very  interested  in  SVG  as  a  standard 
for  mapping  (DocFinder:  8031).  And  check 
out  a  fantastic  example  at  the  same  Doc¬ 
Finder  number  (be  patient,  it  is  slow  but 
worth  it). 

Anyway  in  the  last  of  those  Gearhead 
columns  we  mentioned  an  SVG  editor 
from  Jasc  Software  (www.jasc.com)  called 
WebDraw  that,  at  that  time,  was  in  prere¬ 
lease  beta.  It  is  now  in  full  release  and 
worth  a  serious  look. 

While  there  are  a  few  other  well-devel¬ 
oped  SVG  editors  out  there,  WebDraw  is 
one  of  the  easiest  to  use.  Installation  is  triv¬ 
ial,  and  the  user  interface  very  straightfor¬ 
ward.  There  are  panels  for  creating  and 
modifying  the  image,  inspecting  the  resul¬ 
tant  Document  Object  Model  and  proper¬ 
ties,  and  editing  the  document’s  timeline 
that  controls  the  sequence  and  timing  of 


www.nwfusion.com 


events  that  create  animation. 

The  graphics-editing  facilities  are  pretty 
good,  offering  the  usual  tools  for  drawing. 
There  are  also  effects  such  as  bevels  and 
various  color  fills. 

We  must  note  once  again,  as  in  so  many 
applications,  the  tool  tip  help  —  those  text 
bubbles  that  pop  up  when  the  mouse  hov¬ 
ers  over  a  toolbar  icon  —  doesn’t  always 
appear.  This  is  very  annoying,  and  as  we 
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Jasc  Software 
WebDraw 

1  =  a  w  f  u  I , 

10=insanely  great 


have  seen  it  so  often,  we’re  starting  to  think 
it  may  be  Microsoft’s  problem  rather  than 
one  belonging  to  application  developers 
—  anyone  care  to  comment? 

Anyway,  within  WebDraw  you  can  open 
or  import  SVG  files  (including  compressed 
SVG  images  —  that’s  the  .svgz  or  .svg.gz 
types)  and  import  PNG  and  JPEG  images. 
For  output,  you  are  limited  to  uncom¬ 
pressed  and  compressed  SVG  formats. 

Once  you  have  arranged  all  the  compo¬ 


nents  of  your  image,  you  can  add  anima¬ 
tion.  You  can  also  create  keyframes  on  a 
timeline  where  one  or  more  attributes  are 
to  change.  Simply  select  the  point  on  the 
timeline  when  something  is  to  happen  and 
select  the  objects  that  the  something  is  to 
happen  to  (for  example,  change  color) 
and  apply  the  modification. 

WebDraw  lets  you  examine,  edit  and 
extend  the  underlying  SVG  coding.  You 
can  also  preview  your  creation  in  a  win¬ 
dow  in  WebDraw  or  launch  a  browser  to 
check  out  your  handiwork. 

If  you  are  exploring  what  you  could  do 
with  your  Web  site,  check  out  SVG.  At 
$130,  WebDraw  shouldn’t  break  the  bank. 
WebDraw  is  still  evolving  and  is  hereby 
awarded  eight  gearteeth  out  of  10. 

Now,  as  you  start  to  work  with  SVG 
images,  you  will  need  to  convert  raster 
images  to  SVG.  There  are  a  few  tools  out 
there  that  attempt  to  do  this  tricky  task. 
There  are  “fds  for  SVG”  from  PADC  Lab, 
University  of  Tsukuba  (DocFinder:  8032) 
and  CR2V  from  ChristopheVantighem.This 
tool  seems  to  give  generally  terrific  results, 
but  at  present  there  seems  to  be  a  problem 
with  the  downloaded  ZIP  file  being  cor- 
aipted  (DocFinder:  8033). 

What  do  you  think  of  SVG?  Graphic 
descriptions  to  gearhead@gibbs.com. 


Cool 

Quick 
takes 
on  high 
tech 
toys 


Lord  of  the  Things 


The  Treos  are  coming!  The  Treos  are 
coming! 

If  you  thought  it  was  bad  when  end 
users  started  showing  up  at  work  with 
their  Palm  PDAs  and  Pocket  PCs,  get  ready 
for  the  next  attack  wave  —  Handspring’s 
Treo  Communicator. 

Treo  launches  the  next  wave  in  the 
world  of  combination  phone/PDA  de¬ 
vices.  The  first  generation  of  devices 
(Kyocera  Wireless’ Smartphone  and  Sam¬ 
sung’s  1300  phone)  showed  you  could 
combine  a  Palm-based  PDA  with  a  cell 
phone  into  one  device.  These  devices, 
like  the  first  iteration  of  all  new  things, 
were  larger  and  bulkier  than  a  lot  of  peo¬ 
ple  desired.  Early  adopters  will  try  any¬ 
thing  new,  of  course,  but  these  devices 
weren’t  getting  end  users  to  trade  in  their 
small,  portable  and  comfortable  cell 
phones. 

Treo  may  change  that. 

Treo  is  small  enough  to  be  considered  a 
cell  phone,  yet  large  enough  to  be  an 
effective  and  serious  PDAThe  inclusion  of 
a  thumb-style  keyboard  (on  Treo  180) 


Get  ready  for  the  Treo  invasion 


eliminates  the  awkward  text  input  that 
you  find  on  cell  phones  (Treo  180g 
includes  the  more  familiar  Graffiti  inter¬ 
face  for  Palm-heads).  The  first  two  Treo 
models  will  be  available  this  month 
online,  and  in  March  in  stores,  followed  by 
direct  sales  from  carrier  locations.  Treo 
180  costs  $400  with  wireless  activation, 
and  $550  without  activation.  Later  this 
year,  a  color-screen  version  of  Treo  will 
launch,  and  cost  $550  with  activation 
and  $750  without. 

Handspring  tried  to  enter  the  con¬ 
verged  world  with  its  VisorPhone,  as 
a  Springboard  attachment  that  con¬ 
nected  to  its  Visor  models.  However, 
Handspring  failed,  mostly  because  it 
felt  like  you  were  using  your  PDA  as 
a  phone.  The  bulkiness  of  the  PDA 
didn’t  help  either. 

This  time,  Handspring  takes  the  right 
approach  by  making  it  a  phone  first 
and  foremost,  and  making  the  PDA 
functions  secondary.  First,  Treo  is 
smaller  than  the  Kyocera  and  Sam¬ 
sung  Palm  phones,  small  enough  to  fit 
into  a  jacket  pocket  (like  a  cell  phone). Se 
cond,  the  software  on  the  device  does  a 
better  job  of  integrating  PDA  capabilities 
into  the  phone.  Searching  for  a  phone 
number  and  dialing  it  is  much  easier  on  a 
Treo.  (For  a  review  of  the  end-user  experi¬ 
ence  with  Treo,  go  to  www.nwfusion.com, 
DocFinder:  7933.) 


does  a  good  job  of  imitating  the  wired 
Internet  experience.  But  remember,  on 
the  GSM  network  you’re  only  getting 
14.4K  bit/sec  connectivity, so  the  speeds 
aren’t  there  yet.  With  Global  Package 
Radio  Service  coming  soon,  the  data 
transmissions  will  get  faster,  so  there’s 
hope. 

Likewise,  on  e-mail  “the  bundled  One- 
Touch  mail  application  only  works  with 
Post  Office  Protocol  3  e-mail,  so  getting 
end  users  connected  to  their  corporate 
e-mail  isn’t  an  option  right  now.  However, 
Handspring  says  a  corporate  e-mail 
option  will  come  later  this  year. 

Still,  if  your  company  plans  on  rolling 
out  applications  to  Palm  users  (whether 
wireless  or  not),  Treo  will  support  these 
applications  because  it  runs  on  Palm  OS. 
And  you’ll  still  have  to  worry  about 
encryption  and  security  via  third-party 
VPN  applications,  so  the  data  they 
send  is  safe,  but  you  were  planning 
on  doing  that  with  your  Palm  appli¬ 
cations  anyway,  right? 

For  the  most  part,  though,  your 
end  users  likely  will  fall  in  love 
with  the  cell  phone  features  of 
Treo.  Getting  users  to  take  advantage 
of  the  data  capabilities  with  corporate 
data  will  still  be  up  to  you. 


Send  any  Cool  Tools  info  to 
kshaw@nww.  com. 


Treo  is  a  dual-mode  GSM  phone,  which 
means  end  users  also  will  get  some  data 
capabilities.  This  is  the  area  where  most 
network  executives  will  receive  phone 
calls  from  end  users,  as  they  will  need 
help  setting  up  the  phone  to  access  the 
Internet  and  e-mail. 

For  Internet  surfing, 
Treo  comes  with  the 
Blazer  browser,  which 


Handspring's  Treo  is  small  enough  to  let 
users  trade  in  their  cell  phones. 


WebSphere  software 


THEY  CAME  LOOKING  FOR  THE  SOFTWARE  CHOSEN  BY  LEADING  E-BUSINESSES.  THEY  FOUND: 

WEBSPHERE  at  eBay 

IBM  WebSphere  is  the  fastest-growing  e-business  software  platform:  eBay,  one  of  the  most 
successful  “born  on  the  Web”  companies,  has  turned  to  WebSphere  infrastructure  software  as  it  gets  even 
more  serious  about  e-business.  WebSphere  has  the  scalability  to  build,  launch  and  maintain  a  massive 
around-the-clock  site  like  eBay.  Over  thirty  million  registered  eBay  users  will  rely  on  the  dependability  of 
WebSphere  when  they  buy  collectibles,  electronics  and  B-to-B  services.  Visit  ibm.com/websphere/ebay 


business  software 


IT’S  A  DIFFERENT  KIND  of  WORLD. 

YOU  NEED  A  DIFFERENT  KIND  of  SOFTWARE. 


N'jlwrifkVAirid 1  2/4/02 


EDITORIAL 

John  Di* 

NetCountant 
lets  you  pay  as 
you  go 

If  you  were  looking  for  signs  of  economic  and  industry 
recovery  at  last  weeks  ComNet  show  in  Washington, 
D.C.you  would  have  been  sorely  disappointed.  While 
the  Network  World  Showdown  on  VPN  services  —  hosted 
by  Editorial  Director  John  Gallant  —  drew  more  than  400 
people,  the  show  was  otherwise  eerily  quiet. 

Attendance  was  way  down,  and  the  exhibit  floor  was 
pockmarked  by  empty  booths.  However,  I  did  catch  up 
with  one  company  whose  product,  while  not  inexpensive, 
might  help  large  companies  save  money  in  these  troubled 
times. 

Apogee  Networks’  NetCountant  is  a  charge-back  system 
that  companies  can  use  to  bill  departments  for  band¬ 
width,  applications  (including  e-mail)  and  even  storage. 
Rather  than  trying  to  centrally  throttle  use  of  these  costly 
resources,  the  idea  is  to  encourage  the  consumers  of  the 
resources  to  police  themselves  by  requiring  them  to  pay 
for  what  they  use. 

Apogee  was  founded  in  1997  by  Pablo  Tapia,  who  is 
said  to  have  built  and  managed  global  networks  for  the 
likes  of  Goldman  Sachs  and  Bankers  Trust. Tapia  figured 
out  he  could  use  existing  network  probes  to  collect  infor¬ 
mation  about  network  usage  and  then  boil  that  down  to 
show  where  the  network  dollar  was  going. 

This  so-called  cost  transparency  lets  companies  regu¬ 
late  usage  of  network  resources  just  as  they  would  travel 
and  entertainment  expenses,  says  Andrew  Burroughs, 
chief  marketing  officer  and  general  manager  at  Apogee. 

And  apparently  it  works.  After  using  NetCountant  to  shift 
to  a  usage-based  approach  to  internal  network  billing, 
Fidelity  Investments  is  said  to  have  reduced  WAN  traffic 
by  17%,  resulting  in  $15  million  in  savings  in  one  year. 
While  that  couldn’t  be  verified  by  press  time,  Burroughs 
says  the  return  on  investment  is  typically  seven  to  eight 
months,  which  is  amazing  since  NetCountant  systems  typi¬ 
cally  costs  between  $2  to  $4  million. 

Burroughs  says  installing  NetCountant  usually  requires 
deployment  of  more  probes  to  canvas  the  network  and 
some  customization  to  ensure  the  system  can  properly 
read  probe  log  data.  Other  than  that,  the  hardest  part  of 
implementation  is  deciding  whom  to  charge  for  what 
and  how  much.“The  software  is  easy  to  implement,”  he 
says.The  policy  is  harder.” 

The  company  has  14  customers  today,  including  State 
Street  Bank  and  Texaco,  and  is  targeting  outfits  that  spend 
$10  million  or  more  on  bandwidth. 

Gartner  says  25%  of  the  Fortune  1000  will  have  usage 
based  billing  by  2004.  If  that  proves  true,  Apogee  is  nicely 
positioned  to  capitalize  on  this  trend. 

—  John  Dix 
Editor  in  chief 
jdix@nwu).  com 


www.nwfusion.com 


opinions 


Happy  activation 

1  agree  with  Mark  Gibbs’  opinion  of  Microsoft’s 
product  activation  system  (www.nwfusion.com, 
DocFinder:  7923).  Gibbs  and  I  may  be  somewhat 
paranoid,  but  I’m  afraid  the  reality  will  be  worse 
than  our  worst  predictions.  Saying  the  activation 
control  in  Windows  XP  will  affect  only  users  of 
pirated  software  is  like  saying  the  new  privacy-lim¬ 
iting  “antiterrorist”  measures  will  only  affect  people 
who  have  something  to  hide. 

Already  the  process  to  modify  some  of  the  set¬ 
tings  in  XP  is  more  cumbersome  than  it  is  for  any 
other  Windows  product.  You  have  to  provide  the 
product  key  each  time  you  need  to  install  a  feature 
that  was  not  installed  in  the  original  session  (for 
example,  to  add  a  new  protocol). This  is  time-con¬ 
suming  and  annoying  when  one  is  dealing  with  a 
single  machine  or  a  very  small  network.  I  can  only 
imagine  how  much  fun  it  will  be  to  do  any 
upgrades  or  modifications  to  an  enterprise-size 
network. 

As  Gibbs  says,  there  will  be  no  savings  from  the 
activation  control.  The  only  hope  is  that  there 
will  be  more  people  who  don’t  like  the  new 
arrangement  and  almighty  Microsoft  revises  its 
strategy. 

Marek  Dziedzic 
Partner 
inMark  Consulting 
Kanata,  Ontario 


TchIo  list 

Regarding  “This  year  I’m  definitely  going  to  ...” 
(www.nwfusion.com,  DocFinder:  7922):  I  pity  the 
University  of  South  Florida,  whose  IT  group  is  mar¬ 
keting  its  services  outside  the  university.  I’m  an  IT 

E-mail  letters  to  jdix@nww.com  or  send  them  to  John  Dix,  editor  in 
chief,  Network  World,  1 18  Turnpike  Road,  Southborough,  MA  01772. 
Please  include  phone  number  and  address  for  verification. 


consultant,  and  every  time  I  see  an  IT  group  chase 
external  clients,  it  ends  in  disaster  for  the  business 
—  external  clients  take  priority  over  internal  clients 
as  IT  chases  “real  money”  rather  than  internal 
money.  The  outcome  is  generally  poorer  service 
internally  or  a  misdirection  of  resources,  with  exter¬ 
nal  clients  subsidized  at  the  expense  of  internal 
clients. 

Greg  Priestley 
Director 
asicIT  Pty  Limited 
Sydney,  Australia 

In  reading  your  “to  do”  items  for  2002,  I  was 
aghast  that  Gartner  analyst  Bill  Gassman  recom¬ 
mends  eliminating  inventory  applications  as  a 
cost-cutting  tip  and  advice  for  better  budget-man¬ 
agement.  This  is  not  only  counterintuitive  during 
times  of  tightening  IT  budgets,  when  controlling 
and  tracking  IT  assets  is  critical  to  knowing  where 
to  cut  and  how  to  identify  software  overspending, 
but  also  seems  to  run  counter  to  Gartner’s  long¬ 
standing  advice  that  IT  asset  management  is  the 
key  to  reducing  cost  of  ownership  and  minimiz¬ 
ing  risk. 

In  a  time  when  the  Business  Software  Alliance  is 
fining  companies  thousands  of  dollars  and 
Microsoft  is  bullying  clients  into  expensive  new 
software  licensing  schemes,  IT  managers  should 
dust  off  their  inventory  software,  not  throw  it  out. 

Karen  Kaliski 
Senior  research  analyst 
Tally  Systems 
Hanover,  N.H. 

Editor’s  note:  Gassman  suggests  that  companies 
take  a  census  of  their  network  and  system  manage¬ 
ment  tools  and  weed  out  those  that  they  are  not 
using,  but  for  which  they  are  paying  maintenance 
and  support  fees.  He  does  not  suggest  arbitrarily 
eliminating  applications. 


More  online!  www.nwftision.com  Find  out  what  readers  are  saying  about  these  and  other  topics.  DocFinder  7921 
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TOTALLY  UNPLUGGED 

Ira  Brodsky 

Is  there  anything  we  can  do  to  pull  our¬ 
selves  out  of  this  telecom  depression?  Yes, 
if  vendors  and  companies  focus  on  solu¬ 
tions  offering  short-term  payback  and  long¬ 
term  strategic  value. 

I  suggest  the  industry  redouble  its  efforts  in 
two  key  areas:  storage  networks  and  3G  wire¬ 
less.  These  are  two  of  the  hottest  growth  segments.  Together,  they 
promise  to  put  information  to  more  effective  use  in  crucial  customer 
service,  business  planning  and  workflow  automation  applications. 

Storage  networks  let  organizations  create  vast  information  reposi¬ 
tories,  which  can  be  used  to  capture  data  about  products,  customers 
and  markets.  Putting  a  company’s  information  in  one  virtual  storage 
bin  makes  it  easier  to  share,  manipulate  and  distribute.  Consider  the 
typical  hospital,  where  too  often  information  is  gathered  and  stored 
separately  by  the  clinical,  diagnostic,  pharmaceutical  and  business 
departments.  Bringing  information  together  improves  efficiency, 
reduces  errors  and  saves  money. 

Storage  networks  also  will  play  a  role  in  the  Internet’s  evolution  into 
a  global,  digital-content  library  and  on-demand  delivery  system.  The 
key  to  making  this  happen  is  storage  management  software. 
Virtualization  software  is  used  to  allocate  storage  space  dynamically 
and  efficiently,  and  to  file  and  cache  data. 

Vast  information  repositories  will  come  into  their  own  once  they  are 
integrated  with  high-speed  wireless  communications.  This  is  because 


A  cure  for  telecom  depression 


the  value  of  information  is  directly  related  to  its  freshness,  availability 
and  context. Wireless  is  the  only  technology  that  can  ensure  real-time 
connectivity  wherever  information  is  collected  or  applied. 

Reports  that  3G  wireless  has  been  delayed  are  simply  not  true. There 
are  already  3  million  3G  users  in  South  Korea,  and  3G  networks  will 
come  online  this  year  in  Japan,  the  U.S.,  Brazil  and  several  other  coun- 
tries.These  networks  offer  data  throughputs  starting  at  144K  bit/sec  with 
planned  evolution  to  speeds  in  the  million  bit/sec  range. 

There  are  about  800  million  mobile  phone  users  globally  and  more 
than  90%  of  them  already  use  digital  service.  With  the  migration  to  3G 
services,  the  mobile  phone  industry  will  accomplish  what  local  tele¬ 
phone  companies  promised  30  years  ago  but  never  delivered:  ubiqui¬ 
tous  and  affordable  high-speed  data  services. 

The  combination  of  3G  wireless  and  storage  networks  will  enable 
new  applications  for  database  access  and  digital  content  sharing.The 
first  crop  of  applications  will  deal  mainly  with  field  force  automation, 
location-based  services  and  customer/supplier  relationship  manage¬ 
ment.  Each  of  these  areas  is  ripe  for  development,  because  each 
addresses  real  needs. 

There  is  no  magic  cure  for  telecom  depression.  But  storage  net¬ 
works  and  3G  wireless  can  help  us  work  smarter,  and  that  is  the  only 
path  to  the  next  round  of  growth. 


Storage  net¬ 
works  and  3G 
wireless  can  help 
us  work  smarter, 
and  that  is  the 
only  path  to  the 
next  round  of 
growth. 


Brodsky  is  president  of  Datacomm  Research  in  Chesterfield,  Mo.  He 
can  be  reached  at  ibrodsky@datacommresearch.com. 


REALITY  CHECK 

Thomas  Nolle 


By  now  everyone’s  familiar  with  the  story 
of  Enrons  rise  and  fall.  Here’s  a  com¬ 
pany  that  reportedly  hid  liabilities, 
hyped  its  business  to  analysts  and  tried  to 
influence  politicians.  Sound  shameful?  It  also 
sounds  a  lot  like  our  industry 
Let’s  start  with  hiding  liabilities.  Generally 
accepted  accounting  practices  (GAAP)  have  hamstrung  some  high- 
tech  high-fliers  looking  to  state  the  kind  of  positive  results  that  attract 
interest  from  Wall  Street.  As  a  result,  there’s  been  pressure  to  adopt  a 
different  kind  of  accounting  policy  in  reporting  results:  the  pro  forma 
approach,  which  lets  the  company  hide  a  lot  of  one-time  charges  and 
liabilities  —  like  Enron  is  accused  of  doing. 

But  it  gets  worse,  my  friends.  On  Jan.  15,  The  Wall  Street  Journal 
reported  that  the  Canadian  Securities  Administrators  warned 
Canadian  investors  not  to  rely  on  non-GAAP  reporting  indicators. 
Included  were  terms  like  operating  earnings;  cash  earnings;  adjusted 
earnings;  pro  forma  earnings;  and  earnings  before  interest,  taxes, 
depreciation  and  amortization  (EBITDA).  Have  you  ever  seen  an 
emerging  carrier  that  didn’t  rave  about  becoming  “EBITDA-positive”? 

The  difference  between  the  GAAP  numbers  and  pro  forma  account¬ 
ing  can  be  massive.Some  companies’  GAAP  figures  are  so  bad  in  com¬ 
parison  that  a  chart  cannot  be  drawn  to  scale  showing  both  GAAP  and 
pro  forma  values.  Nearly  every  high-tech  start-up  would  post  notice¬ 
ably  worse  numbers  using  GAAPThat’s  why  they  don’t  want  to  do  it. 
And  everybody  assumes  that’s  how  Enron  was  thinking. 

Then  there’s  hype.  How  many  times  has  our  industry  been  bom¬ 
barded  with  rosy  forecasts  of  hockey-stick  growth  in  some  obscure 
technology  market  space?  Didn’t  we  read  that  Enron  was  going  to  rev¬ 
olutionize  networking  by  trading  bandwidth  like  it  trades  energy?  Gee, 
I  hope  not,  based  on  what’s  now  happened. 

Why  did  this  hype  explosion  happen  at  Enron?  Presumably  to  build 
the  perceived  future  value  of  the  company  and  help  sustain  its  stock 
price.  Does  anybody  think  that  if  Enron  executives  knew  the  bottom 
was  going  to  drop  out,  they  might  have  said  “Gosh,  let’s  go  public  with 


Before  you  throw  stones  at  Enron 


this  and  let  the  stock  tank  so  we  can  be  fair  in  disclosing  what’s  hap¬ 
pening”?  Does  anyone  think  the  latest  softswitch  vendor,  DSL  local 
exchange  carrier  or  metropolitan-area  optical  equipment  vendor  is 
plotting  real  industry  growth  and  contemplating  telling  Wall  Street, 
“Our  basic  value  proposition  has  evaporated  and  we’re  essentially 
waiting  to  file  bankruptcy”?  Isn’t  the  behavior  we  see  all  too  often  with 
hype  in  our  industry  a  parallel  to  what  Enron’s  accused  of  doing? 

Then  there’s  politics.  On  the  key  issue  of  broadband  reform,  every 
special-interest  group  from  regional  Bell  operating  companies  to 
interexchange  carriers  to  equipment  vendors  is  lobbying  Congress, 
and  the  Bush  administration  to  take  steps  to  promote  broadband.  But 
what  steps?  The  ones  that  favor  the  lobbyists’ clients,  of  course.  If  any  of 
these  guys  are  taking  a  stand  in  the  public  interest,  it’s  a  happy  acci¬ 
dent.  A  lobbyist  is  a  paid  manipulator  of  the  political  process.  Enron 
spent  millions  lobbying.  So  has  the  carrier  community,  on  telecom 
reform  alone. 

Now  regulators  at  all  levels  are  being  buffeted  by  consumer  com¬ 
plaints  about  Enron’s  fall.  TV  news  programs  parade  people  who 
have  lost  their  life  savings.  How  many  in  high  tech  have  done  the 
same,  as  one  wave  of  nonsense  after  another  broke  on  the  rocks  of 
market  reality? 

Enron  was  an  energy  trading  company  but  also  a  network  company 
It’s  easy  to  sit  back  and  decry  its  behavior  as  an  aberration, only  periph¬ 
erally  involved  with  our  sacred  space.  Rot.  Every  fault  we  lay  at  Enron’s 
feet,  every  civil  liability  or  criminal  behavior  we  hear  suggested,  could 
be  applied  to  many  in  our  industry 

Where’s  the  outcry  against  vendors  or  carriers  who  give  us  EBITDA 
numbers?  Where’s  the  rejection  of  pro  forma  accounting  on  earnings 
in  networking?  Where’s  the  demand  for  disclosure  of  the  truth  in  mar¬ 
ket  estimates?  Those  questions  are  the  critical  ones,  and  if  we  don’t 
answer  them,  regulators  may  show  up  at  our  doors  in  the  future. 


Every  fault  we 
lay  at  Enron’s 
feet,  every  civil 
liability  or  crimi¬ 
nal  behavior  we 
hear  suggested, 
could  be  applied 
to  many  in  our 
industry. 


Nolle  is  president  of  CIMI  Corp.,  a  technology  assessment  firm  in 
Voorhees,  N.J.  He  can  be  reached  at  (856)  753-0004  or  tnolle@cimi- 
corp.com. 


Vulnerability-assessment  tools  edge  toward  usefulness  in  large  networks. 

Holes  in  your  network 

o  you  know  where  the  holes  are  in  your  network?  Vulnerability-assess¬ 
ment  scanners  can  help  you  find  them  before  hackers  do. 

With  these  products  you  can  identify  many  of  the  major  security  holes 
residing  in  the  systems  on  your  network,  usually  with  just  a  few  mouse 
clicks.  Easily  identifying  weaknesses,  coupled  with  understanding  how  to 


correct  them,  is  a  significant  step  toward  maintaining  a  strong  security  posture. 


However,  vulnerability-assessment  scanners,  which  have  been  on 
the  market  almost  10  years,  still  have  a  long  way  to  go  to  maturity. 
Many  of  these  tools  report  false  positives  and  seem  to  falsely  stand 
by  the  idea  that  the  sheer  number  of  identified  vulnerabilities  — 
regardless  of  accuracy  —  proves  the  products’  overall  worth. 

Even  with  these  problems,  the  importance  of  vulnerability  scanners 
in  corporate  security  infrastructures  is  ballooning.  According  to  1DC, 
revenue  will  grow  to  $657  million  in  2004,  up  from  $359  million  this 
year. 

Overall,  these  tools  come  in  two  varieties:  network-based  and  host- 
based  scanners. 

Network-based  vulnerability-assessment  scanners  focus  on  identify¬ 
ing  issues  with  services, such  as  HTTP  FTP  and  Simple  Mail  Transfer 
Protocol,  running  on  systems  in  a  given  network. They  are  ideal  for 
understanding  what  systems  are  running  on  your  network,  what  ser¬ 
vices  are  running  on  those  systems  and  what  vulnerabilities  exist  in 
those  services.  Network  assessment  scanners  usually  do  not  provide 
as  detailed  information  or  give  you  granular  control  of  specific  sys¬ 
tems  as  host-based  assessment  scanners,  but  they  do  provide  more 
detailed  service  and  network  information.  Plus, you  don’t  need  to 
worry  about  deploying  agents  on  all  machines  as  you  do  with  host- 
based  wares;  you  define  a  network  to  scan,  and  off  you  go. 

The  major  players  in  this  market  are  Cisco’s  Secure  Scanner,  ISS’ 
Internet  Scanner  and  Network  Associates’  Distributed  CyberCop 
Scanner.  EEye  Digital  Security’s  Retina  scanner  is  quickly  gaining 
ground.  We  tested  the  leading  network-based  scanners  (see  review, 
page  52). 

Host-based  scanners  identify  system-level  vulnerabilities  such  as  file 
permissions,  user  account  properties  and  registry  settings,  and  usually 
require  that  an  agent  be  installed  on  any  system  to  be  scanned. The 
agents  report  to  a  centralized  database,  which  a  user  can  tap  for  gen¬ 
erating  reports  and  handling  administration.  Because  agents  are 
installed  on  each  system,  administrators  have  more  control  over  the 
system  than  with  network-based  scanners.  If  you  want  to  maintain 
detailed,  granular  control  over  particular  systems,  host-based  assess¬ 
ment  scanners  can  help.  Many  of  these  products  can  be  combined 
with  enterprise  policy-  management  offerings  to  help  ensure  system 
configurations  remain  in  line  with  defined,  corporate  security  poli- 
cies.The  major  players  in  this  market  are  Symantec’s  Enterprise 
Security  Manager,  BindView’s  bv-Control  and  ISS’ System  Scanner. 

But  the  lines  between  network-based  and  host-based  assessment 
scanners  are  blurring.  Many  network  assessment  scanners  include 
functionality  once  available  only  on  host-based  scanners, such  as 
autofix  features.  Many  also  include  the  ability  to  analyze  registry  per¬ 
missions  and  account  properties. 

A  ■  cw  angle  in  the  vulnerability-assessment  story  is  the  arrival  of 
online  assessment  services  (see  story,  page  56). These  services  pro¬ 
vide  an  automated  and  cost-effective  way  to  stay  up-to-date  on  the 


potential  vulnerabilities  in  your  perimeter  devices.  A  few  of  the  man¬ 
aged  services  can  even  scan  internal  systems. 

As  with  any  growing  technology  market,  new  features  for  vulnera¬ 
bility-assessment  tools  are  on  the  horizon.  Users  want  improved  ease- 
of-use,  one-click  updates  and  better  reporting. Vendors  are  obliging 
by  making  user  interfaces  more  intuitive  and  vulnerability  updates 
quick  and  painless.  For  vulnerability  updates,  many  vendors  are  tak¬ 
ing  the  same  approach  antivirus  companies  took  by  providing  Web- 
enabled  updates.  Symantec  uses  its  antivirus  distribution  infrastruc¬ 
ture  called  Live  Update  to  distribute  its  assessment  updates. 

For  reporting,  users  want  a  variety  of  options.  Executive  summaries 
and  detailed  analysis  reports  are  standard,  but  users  also  want  differ¬ 
ential  reports  comparing  scan  results  over  a  period  of  time. The 
assessment  tools  from  Harris  include  this  functionality  EEye’s  Retina 
scanner  will  include  differential  reporting  inversion  5.0,  due  out  in  a 
few  months.  Users  also  want  to  export  reports  to  Word  documents, 
PDFs  and  HTML  files.  Many  assessment  products  already  support  this 
capability  and  the  rest  should  not  be  far  behind. 

Vendors  are  also  looking  to  boost  their  products’  performance. 
Currently,  many  scanners  are  slow  and  some  cannot  even  handle 
Class  C  IP  networks  without  running  on  a  fairly  hefty  system  (a 
Pentium  III-800-based  server  with  512M  bytes  of  RAM).  With  today’s 
scanners,  evaluating  an  entire  corporate  network  is  not  very  feasible 
on  just  one  system. 

There  is  a  growing  trend  toward  using  automated  “fixes”  for  identified 
vulnerabilities.  While  some  administrators  may  not  want  to  implement 
all  recommended  changes,  especially  on  a  production  system,  giving 
the  administrator  the  option  to  automatically  fix  the  vulnerability  is 
helpful.  If  a  vulnerability-assessment  scanner  identifies  a  registry  key 
with  incorrect  permissions,  one  click  of  the  mouse  on  the  autofix  but¬ 
ton  will  immediately  take  care  of  this  issue.  Otherwise,  the  administra¬ 
tor  would  have  to  log  on  to  the  system,  open  the  registry  editor,  find 
the  registry  key  and  change  the  permissions.  Host-based  scanners  have 
the  advantage  in  this  regard  because  the  agent  physically  resides  on 
the  system  and  can  access  many  more  system  resources  for  the  pur¬ 
pose  of  fixing  a  security  hole  than  a  network  scanner  can. 

Vendors  are  developing  ways  for  network  scanners  to  accomplish 
these  fixes,  though.  PatchLink’s  Update  is  the  most  advanced  in  this 
area,  providing  complete  patch  management  and  administration.  It 
downloads  the  patches  from  its  servers  and  has  them  ready  on  your 
network  for  deployment.  PatchLink  does  everything  for  you  behind 
the  scenes. 

The  good  news  about  this  growing  market  is  that  vendors  are  pay¬ 
ing  attention  to  what  users  need  in  an  enterprise  vulnerability-assess¬ 
ment  tool. The  combination  of  assessment  and  autofix/patch  installa¬ 
tion  is  definitely  the  big  trend  to  watch  in  this  market.  Combining 
these  two  activities  will  save  your  system  administrators  time  and 
resources.  ■ 
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the  past,  there  hasn’t  been  much  good  news  about  the  state  of  vulnerability-assess¬ 
ment  scanners.Their  reputation  has  been  plagued  with  false  positive  reports,  lack  of 
scalability,  lagging  updates  and  inadequate  reporting  tools. 

While  some  areas  still  need  a  bit  of  improvement,  vulnerability  scanners  have  useful 
tools  for  helping  network  professionals  identify  potential  vulnerabilities  and  security  However,  we 
also  found  that  many  of  these  products  may  have  trouble  scaling  to  fit  the  requirements  of  enter¬ 
prise  networks. 


JOHN  MERSEY 


In  our  testing,  we  reviewed  products  from  eEye  Digital  Security, 
Nessus,  Symantec,  Internet  Security  Systems,  NetlQ,  Network  As¬ 
sociates,  PatchLink  and  Harris.  Cisco  and  BindView  declined  to 
participate. 

We  evaluated  how  each  identified  our  network  vulnerabilities; 
what  resources  it  required  to  run  and  then  scale  to  a  larger 
network;  its  reporting  tools;  what  it  offered 
as  security  recommendations  and  aut¬ 
ofix  features;  and  installation  and 
ease  of  use. 

EEye  Digital  Secur¬ 
ity’s  Retina  is  the 
Blue  Ribbon 
Award  winner. 
Harris’  Security 
Threat  Avoidance 
Technology 
(STAT) Scanner 
was  a  close  second, 
but  it  fell  a  bit  short  in 
the  ease-of-use  category. 

PatchLink’s  Update  prod¬ 
uct  was  impressive,  but  its 
support  for  Windows-only 
systems  lowered  its  score. 
In  the  near  future,  Patch- 
Link  will  support  Red 
Hat  Linux,  Solaris,  AIX 
and  NetWare  5.x,  the 
company  says.  We  were 
impressed  that  the  vul¬ 
nerability-assessment 
aspect  of  PatchLink  Up¬ 
date  occurs  behind 
the  scenes.The  only 
information  you  see  is 
the  results  of  the 
analysis,  which  in¬ 
forms  you  of  all  the 
patches  that  need  to 
be  installed  on  each 
system. 

ISS’s  Internet  Scanner 
and  the  open  source  scanner  Nessus  made  good  showings.  Both 
provided  good  analysis  overall,  but  performed  slower  than  STAT 
Scanner  and  Retina.  And  both  missed  a  few  more  vulnerabilities 
than  the  top  performers  in  our  test. 

Symantec’s  NetRecon,  NetIQ’s  Security  Analyzer  and  Network 


Associates’  Distributed  CyberCop  Scanner  had  several  issues  that 
held  them  back  in  our  tests.  NetRecon  performed  very  slowly 
and  identified  vulnerabilities  for  services  and  configurations  that 
were  not  running  on  the  network.  While  NetlQ  identified  quite  a 
few  vulnerabilities  on  our  systems,  it  missed  the  big  ones,  includ¬ 
ing  one  of  the  major  known  Internet  Information  Server  5.0  vul¬ 
nerabilities.  Its  performance  also  lagged  when  scanning  more 
than  a  handful  of  systems. 

Distributed  CyberCop  Scanner  takes  a  good  approach  to  scan¬ 
ning  enterprise  networks  by  distributing  the  load  to  multiple 
servers,  but  its  reliance  on  the  ePolicy  Orchestrator  management 
console  is  frustrating. 

■  Vulnerability  ID 

The  most  important  component  of  our  testing  checked  to  see 
how  accurately  the  scanners  identify  vulnerabilities.  Using  our 
controlled  test  network  (see  How  we  did  it,  page  56),  we  selected 
15  vulnerabilities  we  knew  existed  on  the  test  systems  (see  the 
chart  at  www.nwfusion.com,  DocFinder:  7832  to  find  what  vulner¬ 
abilities  we  looked  for  specifically  and  whether  the  product  iden¬ 
tified  them). We  selected  a  combination  of  Linux  and  Windows 
vulnerabilities  and  a  few  system  configuration  options, such  as 
anonymous  FTP  and  allowing  null  sessions,  that  do  not  follow 
generally  defined  security  best  practices. The  vulnerabilities  we 
selected  covered  a  range  of  services,  including  Windows  domain 
issues,  FTP  servers,  Sendmail  servers,  Web  servers  and  Secure 
Shell  (SSH)  devices. 

The  results  were  a  bit  surprising.  All  products  recommended  we 
disable  the  chargen/echo  service,  anonymous  FTP,  and  ability  to 
create  null  sessions  on  our  systems,  which  is  good.  Enabling 
either  of  these  services  and  enabling  null  sessions  on  Windows 
systems  goes  against  security  best  practices. 

Retina  and  STAT  Scanner  found  the  most  of  the  15  vulnerabili¬ 
ties  on  our  target  list  with  Retina  missing  only  two  Linux  holes 
(SSH  and  wu-ftpd)  and  STAT  Scanner  missing  one  Windows 
(MS01-005)  and  a  few  Linux  (sendmail,  wu-ftpd  and  SSH)  holes. 
Both  products  also  provided  information  on  important  registry 
key  and  account  policy  setting  changes.  PatchLink  Update  also 
identified  all  the  patches  that  needed  to  be  installed  on  the 
Windows  systems. 

Overall, STAT  Scanner  provided  the  most  comprehensive  and 
accurate  list  of  the  vulnerabilities  on  our  network.  STAT  Scanner 
requires  a  SSH  connection  to  Unix  systems  and  it  requires  that 
your  administrator  have  a  user  ID  and  password  to  scan  settings. 
The  documentation  and  graphical  user  interface  (GUI)  say  this 
account  must  have  root  access,  but  that  is  not  the  case.  An  ordi¬ 
nary  user  account  works.  Future  documentation  and  the  next 

See  Vulnerability,  page  54 
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Introducing  the  RS  16000  from  Riverstone  Networks 


It’s  the  new  generation  of  router  built  expressly  for 


Gigabit  and  10-Gigabit  Metropolitan  Area  Networks 


The  chassis-based  RS  16000  delivers  up  to  60  wire 


speed  Gigabit  ports,  along  with  10-Gigabit  Ethernet 


and  CWDM  uplinks  all  in  5  rack  units  -  that's  70%  more 


Gigabit  ports  per  rack  inch  than  the  nearest  competitor. 


For  service  providers,  this  means  more  revenue  per 


rack  and  lower  operating  costs. 


But  the  RS  1 6000  is  more  than  the  highest  density  router 


in  the  industry.  As  a  full-function,  Internet-caliber  metro- 


optimized  router,  it  also  delivers  rich  service  creation 


capabilities.  Through  hardware-based  MPLS,  bandwidth 


carving,  and  extensive  billing  and  accounting,  the  RS  16000 


converts  raw  bandwidth  into  profitable  services  for  carriers 


throughout  the  Metropolitan  Area  Network. 


60  GIGABIT  PORTS,  10-GIGABIT  UPLINKS 
WIRE-SPEED  METRO  ROUTER  WITH  MPLS 

ALL  IN  5  RACK  UNITS 


Contact  Riverstone  Networks  at  1-877-778-9595  or  visit 


riverstonenet.com/nww  to  see  how  we  re  changing  the 


Bandwidth  with  Brains 


lit.  * 

|U[  v 

IWJju 

A.. 

HJa!... 

Jgj 

1  ****  •  , 

1 

Testing  scanner  performance 

Network  World  Blue  Ribbon  Award  winner  Retina,  from  eEye  Digital  Security,  swept  our 

tests  to  determine  how  fast  these  products  could  scan  small,  midsize  and  large  networks  20 


Retina  STAT  Scanner  Internet  Scanner  Nessus  Security  Analyzer  NetRecon 


Small  test  network;  12  systems  ■  Class  C  network;  47  systems  ■  Class  8  network;  800  systems 

Note:  We  did  not  include  the  PatchLink  product  in  this  comparison  because  it  requires  that  agents  be  distributed  to  all  systems 
on  the  network,  and  the  scan  occurs  as  soon  as  the  agent  software  is  installed.The  scanning  times  of  the  CyberCop  Scanner 
depended  on  the  number  of  sensors  we  deployed  throughout  the  test  network(s). 


Vulnerability 
Continued  from  page  52 


GUI  release  will  correct  this  issue. 

Nessus  and  Internet  Scanner  performed 
well,  identifying  most  of  the  Linux  issues 
and  the  major  Windows  vulnerabilities. 
NetRecon  only  identified  a  handful  of  our 
known  vulnerabilities  and  a  few  that  were 
not  even  present  on  the  system.  For  one 
Linux  system,  NetRecon  told  us  we  had 
some  Apache  vulnerabilities,  and  Apache 
was  not  even  running  on  that  system.  Net¬ 
Recon  also  told  us  our  Cisco  router  was 
infected  with  the  Girlfriend  and  Subseven 
Trojans  when  they  were  not  present. 

Security  Analyzer  performed  the  worst, 
identifying  only  our  configuration  issues 
but  failing  to  accurately  report  any  ser¬ 
vice-related  vulnerabilities.  All  the  2,065 
vulnerabilities  identified  by  the  product 
were  host  configurations  such  as  file  and 
directory  permissions,  registry  permis¬ 
sions  and  account  policies.  Security  An¬ 
alyzer  will  also  not  identify  Unix/Linux 
vulnerabilities  without  an  agent  installed 
on  the  system.  Even  when  we  installed 
this  agent,  Security  Analyzer  did  not  iden¬ 
tify  any  of  the  vulnerabilities  on  our  list. 


■  Fixing  the  problems 

After  identifying  the  vulnerabilities  on 
each  system,  these  scanners  generally 
provided  some  tips  on  how  to  correct  the 
problems. The  autofix  feature  is  where 
PatchLink  Update  thrives,  providing  a 
comprehensive  assessment  and  patch 
management  feature  that  lets  administra¬ 
tors  automate  and  centralize  Windows 
patch  distribution  and  installation. 

While  not  as  comprehensive  as  the 
PatchLink  offering,  Retina  and  STAT 


Scanner  provided  a  means  of  automati¬ 
cally  and  remotely  fixing  some  registry 
and  permissions  problems.  In  a  future 
release,  Retina  plans  to  offer  a  means  of 
installing  Windows  patches. 

Internet  Scanner  does  not  provide  any 
autofix  functionality,  but  it  provides  the 
best  step-by-step  instructions  to  fix  identi¬ 
fied  vulnerabilities  for  Unix  and 
Windows  platforms. 

For  vulnerability  descriptions  and  identi¬ 
fication,  each  product  provides  different 
sets  of  data.  Retina  provides  the  most  in¬ 


formation,  including  Bugtraq  IDs,  Common 
Vulnerabilities  and  Exposures  (CVE)  num¬ 
bers,  and  vendor  patch  numbers  where 
available.  ISS  only  lists  the  CVE  number. 
NetRecon  uses  the  CERT  Advisory  num¬ 
ber.  STAT  Scanner  uses  the  Q  ID  number 
for  Microsoft  bulletins,  and  PatchLink 
Update  uses  the  Microsoft  Bulletin  num¬ 
bers.  Comparing  the  output  of  all  these 
scanners  to  identify  exactly  what  vulnera¬ 
bilities  they  are  describing  is  a  cumber¬ 
some  and  arduous  process. 

See  Vulnerability,  page  56 


Net  Results 


RATING 

Retina  4.7 

Company:  eEye 
Digital  Security, 
(866)  339-3732, 
www.eeye.com 
Price:  $5,000  for 
an  unlimited 
license  with  a 
$1,700  annual 
maintenance  fee. 
Pros:  Extremely 
fast  analysis;  good 
autofix  capa¬ 
bilities;  intuitive 
interface;  strong 
vulnerability  identi¬ 
fication.  Cons: 
Few  reporting 
options. 


4.05  RATING 

STAT  Scanner  4 

Company:  Harris, 
(888)  725-7828, 
www.statonline. 
com  Price: 
$12,500  for  an  unl¬ 
imited  license  with 
a  $2,500  annual 
maintenance  fee. 
Pros:  Excellent 
report  options; 
strong  autofix 
capabilities;  fast 
analysis;  strong 
vulnerability  identi¬ 
fication.  Cons: 
Requires  SSH  to 
scan  Linux/Unix 
machines;  inter¬ 
face  is  a  little 
crowded 


RATING 

PatchLink  Update 
3.0 

Company: 

PatchLink,  (888) 
970-1025,  www. 
patchlink.com 
Price:  $1,000  per 
server  and  $12  per 
agent.  Pros:  Ex¬ 
cellent  indenti- 
fication  of  missing 
patches;  installs 
patches  auto¬ 
matically.  Cons: 
Only  works  with 
Windows  systems 
at  the  moment;  no 
printed  report 
options. 


RATING 

Internet  Scanner 

6.2.1 


Company: 

Internet  Security 
Systems,  (888) 
901-7477,  www.iss. 
net  Price:  $9,500 
for  a  250-node 
license  and  a 
$1,900  annual 
maintenance  fee. 
Pros:  Strong 
Linux  identi¬ 
fication;  detailed 
instructions  to 
remove  identified 
vulnerabilities. 
Cons:  Interface  is 
not  very  intuitive. 


3.10  RATING 

Nessus  1.8.10 


Company: 

Nessus,  www. 
nessus.org  Price: 
Open  source. 
Pros:  Very  cost 
effective;  simple 
installation 
process;  good 
vulnerability 
identification. 
Cons:  No  defined 
signature  update 
schedule. 


2.85 


RATING 


RATING 


RATING 


NetRecon  3.5 

Company: 

Symantec,  (800) 
745-6054,  www. 
symantec.com 
Price:  $20,000  for 
an  unlimited  li¬ 
cense  and  a  $3,600 
annual  mainten¬ 
ance  fee.  Pros: 
Simple  installa¬ 
tion.  Cons:  Slow 
performance;  poor 
vulnerability 
identification; 
expensive. 


Distributed  Cyber- 
Cop  Scanner  2.0 


Company: 

Network  Assoc¬ 
iates,  (972)  308- 
9960,  www.nai.com 
Price:  $23  per 
node  up  to  500 
nodes  including 
two-year  maint¬ 
enance  fee.  Pros: 
Highly  scalable. 
Cons:  Difficult  to 
install  and  con¬ 
fusing  to  use;  poor 
user  interface. 


Security  Analyzer 
4.0a 


Company:  NetlQ, 
(888)  323-6768, 
www.netiq.com 
Price:  $60  per 
node  for  20  to  250 
nodes  down  to  $31 
per  node  for  more 
than  5,000  nodes. 
Pros:  Easy  install¬ 
ation  process; 
comprehensive 
registry  analysis. 
Cons:  Extremely 
slow  and  pro¬ 
cessor  intensive; 
poor  vulnerability 
identification. 


What’s  the  score? 

Retina 

STAT 

Scanner 

PatchLink 

Internet 

Scanner 

Nessus 

NetRecon 

CyberCop 

Scanner 

Security 

Analyzer 

Vulnerability  identification  25% 

t 

4 

4 

2 

3 

3 

2 

3 

1 

Reporting  25% 

4 

5 

3 

4 

3 

3 

3 

3 

Installation/ease  of  use  20% 

5 

3 

5 

4 

3 

4 

1 

4 

Recommendations/autofix  20% 

4 

4 

5 

3 

3 

3 

2 

2 

Scalability/resource  use  10% 

5 

4 

4 

3 

4 

2 

5 

2 

TOTAL  SCORE 

4.3 

4.05 

3.65 

3.45 

3.1 

2.85 

2.6 

2.4 

Individual  category  scores  are  based  on  a  scale  of  1  to  5.  Percentages  are  the  weight  given  each  category  in  determining  the  total  score.  ■  Scoring  Key:  5:  Exceptional  showing  in  this  category. 
Defines  the  standard  of  excellence  4:  Very  good  showing.  Although  there  may  be  room  for  improvement,  this  product  was  much  better  than  the  average.  3:  Average  showing  in  this  category.  Product 
was  neither  especially  good  nor  exceptionally  bad.  2:  Below  average.  Lacked  some  features  or  lower  performance  than  other  products  or  than  expected.  1:  Consistently  subpar,  or  lacking  features  being 

reviewed. 
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Vulnerability 
Continued  from  page  54 

For  identifying  patch  locations,  Retina 
and  STAT  Scanner  are  again  at  the  head 
of  the  class, They  provide  direct  links  to 
the  patch  location  or  a  link  to  the  pro¬ 
gram’s  Web  site,  such  as  www.sendmail 
,org  for  Sendmail  vulnerabilities.  STAT 
Scanner  takes  this  one  step  further  for 
Red  Hat  Linux  systems  by  providing 
direct  links  to  Red  Hat’s  packaged  man¬ 
agement  platform. 

■  Reporting 

After  vulnerability  identification,  report¬ 
ing  is  the  next  most  important  feature  of 
any  vulnerability  scanner.  It’s  one  thing  to 
find  the  holes  on  the  network,  it’s  another 
to  present  that  information  to  the  user  in  a 
timely  and  organized  format.  Reporting  is 
fairly  standard  across  the  assessment  scan¬ 
ners  we  tested,  but  a  few  issues  stood  out. 

All  scanners  provided  at  least  HTML  re¬ 
port  output.  NetRecon  and  Internet  Scan¬ 
ner  provided  PDF  exports,  which  is  very 
nice. We  would  have  liked  this  feature  in 
all  the  products. 

But  STAT  Scanner  offers  the  widest  range 
of  reporting  options  by  providing  a  long 
list  of  potential  reports.  If  there  is  a  specific 
way  you  would  like  the  information  dis¬ 
played,  STAT  Scanner  will  have  the  report 
format  available.  Internet  Scanner  and  Net¬ 
Recon  also  provided  a  decent  range  of  re 
port  options,  including  executive  sum¬ 
maries  and  detailed  technical  reports. 

PatchLink  Update  provided  online  re¬ 
ports  detailing  what  patches  are  installed 
on  a  system  and  which  systems  need  spe¬ 


cific  patches.These  reports  are  only  avail¬ 
able  online,  though. We  would  like  to  have 
the  option  to  export  and/or  print  reports. 

Security  Analyzer’s  report  can  be  expor¬ 
ted  to  HTML  or  Word.  However,  it  is  cum¬ 
bersome  to  review. The  information  is 
jumbled  and  not  presented  in  an  easy-to- 
read  format. 

■  Installation  and  ease  of  use 

All  the  products,  with  the  exception  of 
Nessus,used  standard  Windows  installer 
programs.  After  installation, STAT  Scanner, 
Retina,  Internet  Scanner,  NetRecon  and 
Security  Analyzer  were  ready  to  go.  Patch- 
Link  Update  required  agent  installations 
on  each  machine,  and  CyberCop  Scanner 
needed  to  be  configured  through  eFblicy 


Orchestrator  and  have  agents  deployed  to 
systems  that  will  perform  the  scanning. 

To  initiate  a  scan,  most  products  only 
needed  an  IP  address,  range  of  IP  ad¬ 
dresses  and  domain  name  to  start.  System 
identification  is  generally  built  in  to  the 
scanner,  with  the  exception  of  STAT  Scan¬ 
ner.  This  uses  a  third-party  application, 
What’s  Up  Gold  by  Ipswitch.to  identify 
systems  on  the  network. 

The  Nessus  installation  process  went 
smoothly.  We  followed  the  instructions 
found  at  www.nessus.org,  installing  the 
necessary  libraries  and  then  running  the 
Nessus  installation  shell  script. 

Retina  and  Nessus  use  Nmap.the  open 
source  fingerprinting  tool,  to  identify  sys¬ 
tems  running  on  the  network,  what  ports 


are  open  and  what  operating  system  is 
running.  Other  scanners  use  proprietary 
techniques  for  identification. 

NetRecon,  Nessus  and  Retina  did  a  good 
job  identifying  devices  on  the  network, 
including  the  NetScreen  firewall  appli¬ 
ance  and  its  corresponding  management 
server,  SNAP  Network  Attached  Storage 
device,  and  a  Hewlett-Packard  printer. 
STAT  Scanner,  1SS  and  Security  Analyzer 
only  identified  the  Windows  and  Linux 
systems  on  the  network.They  found  the 
active  IP  addresses  for  the  other  devices, 
but  couldn’t  identify  them. 

Updating  each  scanner  to  identify  the 
latest  vulnerabilities  was  simple  across 
the  board.  Out  of  the  box,  all  the  prod¬ 
ucts,  except  Nessus,  provided  the  ability 


How  we  did  it 


lor  our  testing,  we  configured  a  12-system  test  network 
l  that  contained  a  variety  of  platforms  and  configurations: 


■  Red  Hat  Linux  6.2  default  install. 

■  Red  Hat  Linux  7.1  default  install  with  firewall. 

■  Two  Windows  2000  Servers  —  one  running  Microsoft's 
Internet  Information  Server  with  no  service  packs  and  one 
with  Service  Pack  2  acting  as  a  domain  controller. 

■  Two  Win  2000  Professional  systems  —  one  running  with 
no  service  packs  and  one  with  Service  Pack  2. 

■  Windows  NT  —  Service  Pack  6a  and  no  hot  fixes. 

■  NetScreen  firewall. 

■  SNAP  Network  Attached  Storage  Device. 

■  Hewlett-Packard  printer  with  jet  direct  print  serve. 

■  Cisco  2600  router. 

■  Solaris  8  system. 

We  identified  a  list  of  15  vulnerabilities  on  this  network  and 
compared  scan  results  to  this  list  (see  www.nwfusion.com, 
DocFinder:  7832  for  a  list  of  vulnerabilities  used  in  this  test). 


Each  scanner  was  installed  on  a  Pentium  111-800  dual-proces¬ 
sor  system  with  512M  bytes  of  RAM  running  Win  2000  Server 
with  Service  Pack  2.  One  note  —  ISS  does  not  support  running 
Internet  Scanner  on  a  Windows  Server.  Therefore,  we  ran  this 
product  on  a  Pentium  111-500  system  with  256M  bytes  RAM  run¬ 
ning  Win  2000  Professional  with  Service  Pack  2.  We  did  not  no¬ 
tice  any  differences  except  for  the  speed.  For  Nessus,  we  used 
Red  Hat  Linux  7.1  running  on  a  single-processor  Pentium  111-800 
system  with  256M  bytes  of  RAM. 

We  scanned  this  network  with  each  of  the  vulnerability  as¬ 
sessment  scanners  and  compared  the  results.  For  the  scan, 
we  ran  the  most  comprehensive  option  available  on  the  prod¬ 
uct.  For  our  reports,  we  generated  at  least  an  executive  sum¬ 
mary  and  a  detailed  vulnerability  report. 

To  test  performance  on  a  more  enterprise  level,  we  at¬ 
tempted  to  run  scans  on  a  private  Class  C  IP  network  range 
that  contained  approximately  47  Windows  and  Linux  systems. 
We  also  attempted  to  scan  a  private  Class  B  IP  network  range 
containing  500  Windows  and  Linux  systems. 


Vulnerability-assessment  services  on  the  rise 


Like  most  markets  these  days,  the  vulnerability- 
assessment  market  has  a  new  services-based 
component. 

Using  these  services,  organizations  can  remotely 
scan  their  network  perimeter  or  demilitarized  zone  to 
identify  known  vulnerabilities  and  security  weak¬ 
nesses.  With  this  approach,  networks  can  be  easily 
analyzed  from  the  perspective  of  the  outside  attacker 
at  a  much  lower  cost  than  hiring  a  consulting  firm  to 
perform  a  penetration  test.  The  information  then  can 
be  used  to  improve  the  security  on  those  Internet-fac¬ 
ing  systems.  Some  services  even  provide  the  means 
to  scan  internal  systems,  a  task  that  was  previously 
left  to  point  products  like  the  ones  in  our  review.  The 
leading  vendors  in  the  vulnerability  assessment  ser¬ 
vices  market  are  Qualys,  Vigilante,  Foundstone  and 
McAfee. 

With  these  services,  scans  can  be  scheduled,  by  the 
enterprise  user  or  the  service  provider,  to  run  auto¬ 
matically,  with  reports  e-mailed  to  a  designated  user 
or  stored  on  a  secure  server  for  review.  Many  reports 
include  a  differential  analysis  to  help  you  see  how 
your  security  posture  evolves  over  time.  Foundstone 
offers  this  type  of  consulting. 

0  ualys  and  Vigilante  focus  on  providing  just  the 


assessment-scanning  services  and  then  sell  that  ser¬ 
vice  to  other  outfits,  like  consulting  firms,  who  then 
brand  the  vulnerability-assessment  services  as  their 
own.  For  example,  NCC  Networks  provides  vulnerabil¬ 
ity  assessments  to  their  clients  using  the  Qualys 
scanning  engine. 

One  major  benefit  of  online  services  is  the  lack  of 
updates.  Because  the  service  provider  runs  every¬ 
thing,  it  can  develop  signatures  and  updates  for  new 
vulnerabilities  and  automatically  include  them  in  the 
next  scan.  You  do  not  need  to  perform  any  updates. 
As  for  the  timing  of  updates,  service  providers  typi¬ 
cally  have  the  resources  to  get  a  new  update 
deployed  within  a  few  hours. 

Because  these  services  contain  data  about  your 
network  that  any  hacker  would  love  to  find  (it  pre¬ 
vents  them  from  having  to  do  all  the  work),  reports 
are  stored  in  encrypted  databases  and  only  accessi¬ 
ble  with  the  proper  user  credentials.  While  the  data 
must  be  saved  to  generate  comparison  reports,  not 
all  services  keep  individual  reports  available.  Vigi¬ 
lante's  SecureScan  creates  a  PDF  report  that  is  only 
stored  on  their  systems  for  14  days. 

Like  their  shrink-wrapped  counterparts,  online  vulnera¬ 
bility  scanners  take  different  approaches  in  how  they 


determine  whether  a  vulnerability  exists  on  a  system. 
Foundstone  takes  an  analytical  approach  and  ensures  a 
vulnerability  actually  exists  on  a  system  before  report¬ 
ing  it.  This  greatly  reduces  the  number  of  false  positives, 
but  it  also  does  not  give  you  the  big  picture. 

Foundstone  sacrificed  some  detailed  information, 
such  as  general  service  messages  (for  example,  that 
Telnet  is  running  on  this  system)  to  focus  on  vulnera¬ 
bility  identification.  In  reporting,  most  services  pro¬ 
vide  more  information  on  system  configuration,  such 
as  default  Microsoft's  Internet  Information  Server 
directories.  While  these  are  not  specifically  defined 
vulnerabilities,  they  can  provide  information  and 
avenues  of  attack. 

Other  online  scanners,  such  as  Qualys  and  Vigilante 
SecureScan,  use  open  source  tools,  such  as  Nmap 
and  Nessus,  combined  with  in-house  developed  tools. 
SecureScan  takes  this  even  one  step  further  and 
combines  existing  commercial  scanner  products  into 
an  online  service. 

Assessment  services  are  ideal  if  you  are  looking  for 
a  hands-free,  regularly  scheduled  scan  of  your  Inter¬ 
net-facing  devices:  do  not  want  to  be  concerned  with 
keeping  up-to-date  with  newly  identified  vulnerabili¬ 
ties;  or  want  a  third-party  constantly  helping  you  eval¬ 
uate  and  monitor  your  network. 

—  Mandy  Andress 


to  automatically  download  updates  over 
the  Internet.  Security  Analyzer  actually 
checks  each  time  the  product  is  started 
and  alerts  you  that  updates  are  available. 
Symantec’s  process  is  the  smoothest,  us¬ 
ing  its  Live  Update  infrastructure. 

Nessus  relies  on  the  Linux  community 
to  provide  vulnerability  updates.  Several 
individuals  have  written  scripts  that  will 
go  out  to  the  Internet  to  download  and 
install  the  latest  vulnerability  signatures. 
Once  this  process  is  set  up,  updates  can 
be  seamless  and  automatic. 

Update  availability  varies  from  vendor 
to  vendor. 

They  all  say  they  release  updates  for 
major  vulnerabilities  as  soon  as  they  are 
available,  which  can  be  a  few  hours  to 
several  days  or  weeks.  STAT  Scanner  re¬ 
leases  new  updates  on  the  eighth  day  of 
each  month.  NetRecon  releases  updates 
every  other  week. 

Retina  has  the  best  user  interface  with 
its  slick  colors  and  intuitive  layout.  STAT 
Scanner  provided  a  lot  of  functionality  in 
its  product,  and  its  interface  shows  that 
because  it  is  a  bit  cluttered  with  informa¬ 
tion  and  small  icons. 

The  Security  Analyzer  interface  is  the 
same  as  the  one  used  by  WebTrends  re¬ 
porting  software,  so  many  users  may  find 
this  product  strangely  familiar.  Distributed 
CyberCop  Scanner  uses  the  eFblicy  Or- 
chestrator  for  management,  and  was  diffi¬ 
cult  to  navigate  and  use. 

The  Nessus  interface  runs  in  X  Windows 
and  is  a  simple,  low-frills  application.The 
PatchLink  Update  interface  is  a  slick  Web- 
based  interface  that  anyone  familiar  with 
any  Web-based  administration  tool  will 
find  easy  to  use. 

Retina  is  lightning  fast,  scanning  our 
12-system  test  network  in  less  than  5 
minutes.  STAT  Scanner  also  performed 
well,  taking  about  20  minutes.  Internet 
Scanner  took  the  longest  in  our  first 
round  of  tests,  having  to  be  stopped 
after  eight  hours  because  it  hung  on 
the  analysis  of  the  management  IP  for 
the  NetScreen  firewall.  After  removing 
NetScreen  from  the  test,  Internet  Scan¬ 
ner  took  two  hours  to  complete. 

After  testing  in  our  self-contained  12- 
system  lab  network,  we  ventured  out  into 
the  real  world  to  see  how  these  products 
would  act  on  more  enterprise-sized  net¬ 
works.  We  started  slow, scanning  a  net¬ 
work  with  47  active  Windows  and  Linux 
systems.  Retina  still  flew  through  the  pro¬ 
cess,  completing  the  Class  C  scan  in 
about  15  minutes.  Security  Analyzer 
never  finished. 

After  scanning  about  20  systems, 
Security  Analyzer  overloaded  the  sys¬ 
tem  resources  and  could  not  finish. 
NetlQ  tech  support  told  us  we  needed 
more  RAM.  In  our  experience,  the  sys¬ 
tem  necessary  to  scan  a  network  with 
the  NetlQ  product  would  be  much  big¬ 
ger  than  any  organization  would  be 
willing  to  purchase. 

We  then  moved  on  to  a  larger  private 
network  that  contained  approximately 
500  systems.  Retina  still  proved  to  be  the 
fastest,  completing  the  scan  in  a  little 
more  than  two  hours. 

Vulnerability-assessment  scanners  are 


improving,  but  many  are  still  spotty  with 
vulnerability  identification,  and  they  have 
not  been  developed  to  efficiently  scan 
large  networks. 

Retina  and  STAT  Scanner  stood  above 
the  rest  of  the  crowd,  but  they  missed  a 
few  vulnerabilities  on  our  list.  As  new 
products  are  released,  it  will  be  interested 
to  see  whether  vulnerability  identifica¬ 
tion  and  scalability  improve  to  better 


suit  the  enterprise. 

Andress  is  a  network  security  engineer  at 
TiVo  and  a  frequent  contributor  to  many 
publications.  She  has  also  authored  several 
books,  including  Surviving  Security  Andress 
is  also  active  on  the  conference  circuit, 
speaking  at  Black  Hat,  NetWorld+  Interop, 
and  numerous  other  conferences.  She  can 
be  reached  at  mandy@arcsec.com 
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Pie  Top  ISP  Report 

How  is  your  dial-up  ISP  performing? 


December  2001 


B  is  your  ISP  measuring  up? 
Find  out  with  our  Top  ISP 
Report,  a  joint  venture  be¬ 
tween  Network  World  and 
eTesting  Labs'  Internet 
BenchMark  service  (www. 
etestinglabs.com).  The  data 
at  right  is  for  December  2001; 
each  month  you  can  go  online 
at  Network  World  Fusion  for 
the  latest  data. 

The  chart  at  right  shows  the 
top  dial-up  ISPs  in  the  market, 
and  how  they  performed  in 
eight  metrics,  as  determined 
by  eTesting  Labs'  Internet 
BenchMark  data.  We  analyzed 
21  ISPs  (check  out  Network 
World  Fusion  for  the  list);  if 
your  ISP  isn’t  listed  among  the 
top  performers,  ask  them  why 
they’re  not  performing  as  well 
as  their  competitors. 


Top  ISPs  profile, 
December  2001 

Network  World  analysis 

National  retail 

AT&T  WorldNet  •  Wins  in  a 
squeaker,  with  a  strong  Earth- 
Link  in  a  close,  close  second. 

Regional  retail 

PacBell  •  Ver  y  strong  showing 
in  key  categories  makes  this 
a  winner. 

Business-to-business 
McLeodUSA  •  Very  good 
overall  performance  in  all 
categories. 


Our  data  conics  from  (Testing  Labs  and 
it's  Internet  RendiMark  division. 

Nolwork  I  hid  takes  the  data  and 
applies  statistical  analysis  to  rale  the 
relative  performance  of  each  ISP  com¬ 
pared  with  the  oilier  ISPs  within  the 
same  market  classification  (national, 
regional  or  husmess-to  business  ISP). 
Based  on  that  analysis,  we  rank  the  top 
ISPs  for  the  month  feted.  Tint  cltart  on 
Tight  lists  Hie  to))  llireo  ISPs  that 
evjiijnn^ove  the  average  for  the  moi- 
‘K  listed  wit!  mi  that  dassnxyim 


National 

Regional  ISPs 

B2B  ISPs 

Initial  modem  speed  H 

AT&T 

Verizon- East 

AT&T  (6RS) 

Measurement  of  the  negotiated  connection  speed  to  your 

Verizon-West 

BellSouth 

Sprint 

ISP  once  the  call  has  successfully  gone  through. 

Broadwing 

Qwest 

Genuity 

Average  for  market: 

49.07K  bit/sec 

49.06K  bit/sec 

49.07K  bit/sec 

Average  time  to  log  on  ■ 

AT&T 

BeHSenth 

AT&T  (6NS) 

Reflects  the  time  taken  to  connect  and  authenticate  to  a 

EarthLink 

Ameritech 

Sprint 

provider  network  access  server  once  the  modem  takes  the 

Prodigy 

SBIS 

Genuity 

line  off-hook. 

Average  for  market: 

30.26  seconds 

31.06  seconds 

28.61  seconds 

Average  download  time  ■ 

CompuServe 

PacBeti 

Sprint 

The  time  taken  for  the  Web  page  to  download,  including 

AOL 

BellSouth 

McLeodUSA 

all  page  content.  Calculated  by  measuring  the  time  from 

SBIS 

AT&T  (GNS) 

the  first  HTTP  TCP  packet  being  sent  to  the  server  until 

the  last  HTTP  TCP  connection  has  terminated. 

Average  for  market: 

25.57  seconds 

5.14  seconds 

26.41  seconds 

Average  DNS  lookup  ■ 

AT&T 

PacBefl 

MdeudUSA 

The  time  from  sending  the  first  DNS  query  until  a  response 

Prodigy 

SBIS 

WorldCom 

is  received  from  any  query  This  reflects  the  end-user  per- 

EarthLink 

Qwest 

AT&T  (GNS) 

ception  of  the  DNS  resolution  time,  including  retries. 

Average  for  market: 

501.72  msec 

436.10  msec 

600.82  msec 

Average  Web  throughput  ■ 

Prodigy 

PacBeB 

IfcLeodUSA 

The  effective  transfer  rate  of  the  connection.The  average  of 

Broadwing 

SBIS 

Sprint 

these  Web  throughput  measurements  is  presented  in  the 

AT&T 

Qwest 

reports.Throughput  does  not  necessarily  reflect  the  band- 

width  of  the  connection,  but  rather  the  effective  Web 

throughput  experienced  using  a  connection. 

Average  for  market: 

4.97  byte/see 

5.14  byte/sec 

5.36  byte/sec 

Evening-hour  call  failure  rate  M 

EarthLink 

Verizon-East 

McLeodUSA 

How  often  a  modem  call  to  the  provider  gets  through  sue- 

AT&T 

BellSouth 

Genuity/ 

cessfully  during  evening  hours.  A  failure  would  include  a 

Verizon-West 

SBIS 

Sprint  (tie) 

busy  signal,  ring  no  answer,  modem  problem  or  logon  fail- 

a 

V 

V 

ure.The  lower  the  CFR,  the  better. 

r 

f 

f 

Average  for  market: 

5.1% 

2.6% 

1.7% 

% 

Business-hour  call  failure  rate  M 

Verizon-West 

Verizon-East 

WorldCom 

How  often  a  modem  call  to  the  provider  gets  through  sue- 

MSN 

BellSouth 

AT&T  (GNS) 

cessfully  during  weekday  business  hours.  A  failure  would 

AT&T 

Ameritech 

McLeodUSA 

include  a  busy  signal,  ring  no  answer,  modem  problem  or 

m 

W 

1 

logon  failure.The  lower  the  CFR,  the  better. 

i  Jm 

r 

f 

Average  for  market: 

5.7% 

4.8% 

2.9% 

Average  total  Web  fail/timeout  a 

Verizon-West 

BeOSouth/ 

AT&T  (GNS)/ 

Any  error  message  that  appears  as  a  dialog  box  for  the 

Broadwing/EarthLink/ 

PacBell  (tie) 

Sprint  (tie) 

Internet  Explorer  browser  is  considered  a  Web  page 

Prodigy  (tie) 

SBIS 

McLeodUSA 

failure.  Any  download  that  takes  longer  than  4  minutes 

1 

1 

to  complete  is  canceled  and  considered  a  Web  page 

timeout.  A  low  percentage  is  considered  better. 

Average  for  market: 

.3% 

1.1% 

.4% 

Online! 

A  complete  REPORT  and  list  of  ISPs  tested  ■  ARCHIVE  of  our  previous  monthly  reports 


DOCFINDER: 


6727 


www.nwfusion.com 
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Honors  math 


IT  executives  learn  how  to  bolster  a  project  with  solid  figures  at  MIT  seminar. 


■  BY  LAUREN  GIBBONS  PAUL 

CAMBRIDGE,  MASS. - As  she  headed  into  a  two-day  seminar  on  the  fundamentals  of 

finance,  Cheree  Rumley  looked  forward  to  a  review  of  some  of  her  favorite  subjects:  net 
present  value,  internal  rate  of  return,  EBITDA.  You  see,  Rumley  is  a  lot  more  business- 
savvy  than  most  IT  executives.  In  addition  to  undergraduate  and  graduate  degrees  in 
electrical  engineering,  the  project  manager  has  an  MBA. 


Discounted  cash  flow:  Method  of  evaluating 
long-term  projects  that  factors  in  the  value  of 
money  overtime. 


Internal  rate  of  return:  The  discount  rate  at 
which  a  project's  net  present  value  equals  zero. 


Net  present  value:  Present  value  of  cash  inflows 
minus  present  value  of  cash  outflows;  measure 
of  how  much  wealth  an  investment  will  bring. 


SOURCE  ANALYSIS  FOR  FINANCIAL  MANAGEMENT.  ROBERT  HIGGINS. 
IRWIN  MCGRAW-HILL 


ny’s  income  statement  and 
balance  sheet.  (No, 
they’re  not  the 
same  thing.  The 
balance  sheet  is 
a  snapshot  of  a 
company’s 
perfor¬ 
mance  at 
one 


Before  starting  her  position  with  Cingular  Wireless  in 
Atlanta,  Rumley  attended  the  financial  seminar  to  brush 
up  on  her  financial  acumen.  “1  feel  it’s  important  to  under¬ 
stand  all  the  different  aspects  of  business.  I  didn’t  want  to 
just  understand  systems  and  IT,  ”  she  said. 

Rumley  and  more  than  50  others  gathered  with  coffee 
cups  and  Hewlett-Packard  calculators  in  hand  on  Dec.  12 

at  the  Hyatt  Regency  for  a  sem- 


Talk  the  talk 


Earnings  before  interest  and  taxes:  Net  sales 
minus  cost  of  goods  sold  before  interest  or  taxes; 


Manager  Cheree 
of  Cingular 


inar  called  “Fundamentals  of  Finance  for  the  Technical 
Executive.”  Led  by  Professor  David  Scharfstein  of  the 
Massachusetts  Institute  of  Technology  Sloan  School,  the 
crash  course  aimed  to  familiarize  IT  executives  and  other 
technical  professionals  with  financial  concepts  so  they 
could  better  communicate  with  their  companies’  CFOs. 

“We’re  going  to  help  you  learn  to  put  together  convinc¬ 
ing  financial  business  cases,”  Scharfstein  said,  adding 
alarmingly  that  the  seminar  would  cover  his  entire  Sloan 
School  finance  fundamentals  course  in  two  days. 

Most  attendees  had  much  less  exposure  to  financial 
concepts  than  Rumley.  “I  just  want  to  be  able  to  track  the 
conversation,  not  understand  how  to 
really  apply  this  stuff,”  said  one 
attendee.  However,  Rumley’s 
new  job  will  require  her  to 
cost-justify  projects.  “You  have 
to  understand  how  a  project 
adds  value  from  a  return  on 
investment  point  of  view,”  she 
said. 

The  first  day  was  spent  learn¬ 
ing  how  to  read  a  public  compa- 

and 


MW 

mf 
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point  in  time.  An  income  statement  records  the  flow  of 
resources  over  time.)  Deciphering  these  statements  is  an 
important  way  to  judge  a  company’s  performance  and  to 
determine  whether  it  is  faring  better  than  competitors. 

The  second  day  of  the  seminar  was  devoted  to  evaluat¬ 
ing  the  financial  merit  of  a  project  or  a  company.  Many 
attendees  seemed  excited  at  the  prospect  of  gaining  valu¬ 
ation  and  estimation  tools  they  could  bring  home  to  wow 
the  bean  counters.  However,  the  bad  news  is  that  calcu¬ 
lating  a  project’s  worth  is  highly  complex.  A  back-of-the- 
envelope  calculation  of  return  on  investment  is  not  likely 
to  satisfy  your  CFO  or  controller. 

Calculating  a  project’s  value  using  an  established  metric 
such  as  net  present  value  (NPV)  or  interned  rate  of  return 
(IRR)  is  a  complicated  process  requiring  a  boatload  of 
financial  data,  many  critical  assumptions  and  a  good  engi¬ 
neering  calculator.  You  cannot  begin  to  calculate  NPV 
without  first  knowing  how  to  calculate  the  discounted 
cash  flow  (DCF)  value  of  the  money  the  project  will  cost. 
The  principle  is  that  a  dollar  today  is  worth  more  than  a 
dollar  tomorrow,  and  the  “discount  rate”  is  the  variable  by 
which  you  reduce  a  dollar’s  value  depending  on  when  the 
project  will  take  place. 

The  NPV  is  the  present  value  of  revenue  associated  with 
the  project  minus  the  present  value  of  outgoing  cash  asso¬ 
ciated  with  it.  It’s  really  a  measure  of  how  much  money  a 
project  or  acquisition  is  expected  to  bring  to  a  company. 
The  actual  calculation  is  incredibly  complex.  One  easy 
rule  of  thumb:  To  extract  the  most  value  for  the  share¬ 
holders,  a  company  should  undertake  positive  NPV  pro¬ 
jects  and  avoid  negative  NPV  projects. 

Say  you’re  trying  to  make  the  case  to  upgrade  from 
Windows  NT  to  Windows  2000.  Whether  you  should 
undertake  the  project  will  depend  on  if  the  net  discounted 
cash  flows  from  the  project  are  positive  or  negative. 
Hypothetically,  let’s  say  it  would  cost  $1  million  today  for 
the  company  to  undertake  the  upgrade.  Assume  the  pro¬ 
ject  will  return  a  half-million  dollars  in  one  year  and  then 
another  $600,000  in  two  years.  Is  this  a  good  investment? 

If  the  opportunity  cost  of  having  the  $1  million  tied  up  for 
the  one-year  duration  of  the  project  is  10%,  then  the  net 
present  value  of  the  project  would  be  $-.05  million.  Given  • 
that  the  NPV  is  negative,  this  is  not  a  good  investment.  ; 

With  an  MBA  under  her  belt,  Rumley  wasn’t  scared  off  by.  ; . 
any  of  these  concepts  or  equations.  In  fact,  the  seminar 
served  as  a  useful  refresher  for  theories  and  tools  that  she  ’ 
expects  to  use  every  day  in  her  job.  “I  interface  with  the 
finance  department  all  the  time,  and  I  need  to  speak  their  ) 
language,”  she  says. 

Rumley  advises  all  IT  managers  tq  attend  a  seminar  such 
as  this  one. 

“You  really  need  to  know  the  basics,”  Rumley  says.  “Yc 
can’t  be  so  strictly  focused  on  the  systems  and  not  the  I 


tom  line.” 


Gibbons  Paul  is  a  freelance  writer  in  Waban,  Mass,. . 

can  be  reached  at  laurenpaul@mediaone.net.  > . 
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KVM  Switches 


Server  switches  designed  to  increase  system  availability  and  manageability 

•  4  and  8  port  models  available:  expandable  to  support  up  to  64  servers 

•  Models  available  that  support  Sun,  USB  and  PC  servers  simultaneously 

•  Built-in  scanning  feature  allows  you  to  automatically  monitor  your 
computers  without  intervention 

•  On  Screen  Display  (OSD)  functionality,  advanced  security  features 


Look  for  these  other  great 
rack  accessories  horn  APC: 

Fixed  and  Sliding  Shelves 
Cable  Management  Shelves 
Fans 

Keyboards/Keyboard  Drawers 
Stabilization  Kits 
Power  Distribution  Units 

Visit  www.apc.com 
for  more  information! 


APC:  UPSs  and 

APC,  the  name  you  trust  for  power  protection,  also 
offers  a  comprehensive  line  of  non-proprietary  racks, 
rack  accessories  and  management  tools  that  provide 
you  with  the  flexibility  to  implement  a  highly  available, 
multi-vendor  environment.  APC  allows  you  to  create 
a  rack  environment  with  the  level  of  availability  you 


So  Much  More 

require,  and  provides  you  with  the  accessories  and 
management  tools  to  maintain  that  level  of  availability 
over  time.  Our  expert  Configure-to-OrderTeam  can 
custom  tailor  a  complete  rack-mount  solution  to  suit 
your  specific  requirements.  Contact  APC  today  and 
protect  your  rack  application  with  Legendary  Reliability'”. 


Configure  your  racks  with  APC.  Simply  visit  promo.apcc.com  today! 

Key  Code  e146y  •  Call  888-289-APCC  x6345  •  Fax  401 -788-2797 


Legendary  Reliability' 


NetShelter®  VX  Enclosures 


Next  generation,  high-quality  enclosures 

•  Fully  ventilated  front  and  rear  doors  with  enhanced  ventilation  pattern  maximize  airflow 

•  Overhead,  base  and  side  cable  access  provides  easy,  integrated  cable  management 

•  Rear  Cabling  Channel  (42"deep  versions  only)  allows  for  easy  installation, 
access  and  serviceability  of  both  data  cables  and  power  distribution  cables 

•  Available  in  multiple  configurations:  35.5"  deep,  42"  deep,  beige  or  black 


Environmental  Monitoring  Unit 

UPS  card  for  network  administrators  to  monitor  environmental 
conditions  in  rack,  computer  room  and  data  center  environments 

•  Sensors  continuously  monitor  the  temperature  and  humidity  of  equipment 

•  Four  user-definable  external  inputs  allow  use  with  sensors  for  fire, 
water,  smoke,  unauthorized  entry  and  physical  security 

•  Communicates  information  in  a  variety  of  formats  to  ensure  that  your  application  is  supported 


ProtectNet® 


Data  line  surge  suppressors  for  comprehensive  network/PC  system  protection 

•  Protects  against  surges  and  electrostatic  discharge  traveling  through  data  lines 


LCD  Monitors 


High  quality  rack-mount  LCD  monitors  designed  to  maximize 
space  in  a  data  center  environment 

•  Provides  optimal  functionality  while  utilizing  only  1U  (1.75")  of  rack  space 

•  Includes  15"  LCD  monitor,  integrated  keyboard  and  integrated  pointing  device 


Cables 


APC  offers  a  comprehensive  line  of  cables  and  connectivity  solutions  to 
fulfill  the  connectivity  requirements  of  any  application  or  environment 


NetShelter®  Open  Frame  Racks _ ^ 

Economical  open  frame  solutions  for  wiring  closets  and  data  center 
networking  applications 

•  Designed  to  accommodate  networking  devices  such  as  hubs,  routers  and  switches 

•  Industry  standard  7  high  design  provides  45U  of  equipment  mounting  space 

•  Self-squaring  design  allows  one-person  assembly 

•  Made  of  high-strength  6061 -T6  structural-grade  aluminum 

MasterSwitch™  Series _ 

Remote  power  distribution  for  network  administrators 

•  Users  can  configure  the  sequence  in  which  power  is 
provided  to  individual  receptacles  upon  start-up 

•  Built-in  Ethernet  interface  for  direct  connection  to  LAN 

•  Individually  control  8  on-board  power  outlets  for  .  .  .  , .  . . 

.  , r  ,  ,  shown  mounted  inside 

complete  and  flexible  management  of  attached  equipment  NetShelter  VX 


©2002  American  Fbwer  Conversion  All  Trademarks  are  the  property  of  their  owners  APC4A1  ERJSa  •  FowerFax  (800)  347-FAXX  •  E-mail:  apanfo@apcc.com  •  132  Fairgrounds  Road,  West  Kingston,  Ri  02892  USA 
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JTK-2100 
Network 
Monoger  t  Kit 


Outfitter  of  Tools  and  Test  Equipment 
for  Network  Professionals 

Tool  Kits,  Specialty  Tools  &  Test  Equipment  plus 
technical  books,  network  accessories,  workstations, 
diagnostics,  cable  equipment,  and  much  more. 

^  ✓  1 00%  Satisfaction  Guaranteed 

Lifetime  Guarantee  I  ~ - -  L 

on  Jensen  Brand  I  J  J€|UCcm 

Hand  Tools  j  -*-■ 

✓  Free  Technical  Support 


Call:  800-426- 1 194 
www.jensentools.  com 

E-Mail:  jensen«stanleyworks.com 
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Crow  your  Network... 

Buy  BIZI's  quality  pre-owned 
Networking  Hardware 
and  save  up  to  80% ! 

•  Up  to  One  Year  Warranty 

•  Large  Stock 

•  Immediate  Delivery 

•  10  Years  in  Business 

•  100%  30-Day  Money-Back  Guarantee 

www.bizint.com 

/jin  info:  bizint.com 
f  HI/I  (315)  458  9606 

(877)  438-2494 

CISCO,  3-COM,  CABLETRON/ENTERASYS,  NORTEL/BAY  NETWORK, 
EXTREME,  FOUNDRY,  JUNIPER,  and  FORE/MARCONI 


Solutions 


NTI  Has  The  Answers 


mUTFORM  SERVER 
CONTROL  IS  EASY! 

I  want  flexible  control  Control  up  to  128  computers 
without  spending  a  with  one  keyboard,  monitor 

and  mouse. 


fortune!” 
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■  NEW  -  Up  to  8  port*  In  1  rack  unit 
r»  demount  < 
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BUY  ONLINE  at  www.nti1.com  Email:  88le8@nti1.com 


800-742-8324 


■  Available  with  2,  4,  8, 12, 16,  24  or 
32  porta. 

a  Dedicated  Internal  micro proceaaora 
that  emulate  the  keyboard  and 
mouse  presence  to  each  attached 
computer  so  all  computers  boot 
error-free  1 00%  ot  the  time, 
a  Crisp  and  clear 

1800x1200  resolution. 


kht 


LOW  COST  KWH  SOLUTIONS 


1275  Danner  Drive  •  Aurora,  OH  44202 
330-562-7070  •  ^AX:  330-562-1999 
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GET  MCSE,  CISCO,  OR  A+  CERTIFIED...^!// 


With  SmartCertify’s  ClassWare™  You  Get: 

•  Courseware  Developed  in  Partnership  With  Industry  Leaders 

•  24-hour  Online  Mentoring 

•  Online  Seminars,  Workshops  and  References 

•  Unlimited  Telephone/Email  Access  to  IT  Training  Consultants* 

•  Hands-on  Interactive  Exercises 

•  Practice  Assessment  Tests 

•  Test  Prep  Exams 

•  Money-back  Certification  Guarantee** 

I’m  interested  in  Certification  for: 

□  MCSE  □  Cisco  □  A+  Technician 


Name 


Company 

Address 

City 

State 

ZIP 

Phone l  ) 

Fax!  ) 

Email 

Call,  mall  or  fax  TODAY  for  info  on 
our  guarantee  and  a  FREE  catalog! 

1S77-TR AIMING 
- - - 

,*  SmartCertify  Direct, 

0/7  lCH  i  LerilTy  a  SmartForce  Company 
-  n;^v4  25400  U  S.  19  N.  #285. 

UU  CL  l  Clearwater,  FL  33763 
Prepannq  You  (800)475-5831  •  (727)724-6994 

for  a  Successful  IT  Career  p^  (727)726-6922 


(Daytime  Phone  Number  s  Necessary  lo  Process)  Network  World  Deck  ’Not  available  for  some  courses.  "Call  for  details. 


Reliable  KVM  Switch  Control  Over  IP 


f  Control  y0Ur  - 

Servers  from 

Anywhere! 


■  Complete  control  of  your  servers  over  IP 

■  Remote  notification  and 
monitoring 

■  Compatible  with  your 

existing  KVM  Switches  VKSAjwg 

■  Less  than  half  the  cost  of 
similar  products! 


For  more  information  or  a 
FREE  brochure  visit: 


www.startech.com/KVM  NW  StarTech.com 


Get  the  Rack  You  Need  Without  Breaking  Your  Budget 


The  NetWorkRack  Offers  You: 

'Four  Point  Mounting 

*M6  Rails  for  all  your  bracket  requirements 
'Expandable  Depth  from  30"  to  40" 

'Easy  Set-Up 

'Equipment  Mounting  Hardware  Kit 

Available  in  84”,  72",  48"  heights. 
Customized  sizes  also  available. 

Contact  us  for  pricing  on  your  specific  requirements. 

www.notworkcenter.com 

AMERICAN  NETWORK  PRODUCTS 


NWCL 


For  Faster  Service 

Fax  to:  (31 5)  458-9493 

or  call  us  at:  (877)  438-2494  (SIS)  458-9606 

www.bizint.com 

Name _ 

Company - 

Address _ 

Chy - 

State _ Zip - 

Ph _ .E-Mail _ 

NWW1/02 

J  Yes 

I  am  looking  to  purchase  pre-owned  Networking 
hardware.  Please  contact  me  to  discuss  pricing. 

J  Yes 

I  have  Networking  equipment  for  sale 
or  to  trade-in  to  BIZI 

My  need  is: 

□  Immediate  □  J0-90  Days  □  Longer  Term 
Comments _ 
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BIZI  Int,  Inc 

P.0.  Box  305 
119  Church  Street 
No.  Syracuse,  NY 
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Dept.  599 

7815  S  46th  Street 

Phoenix,  AZ  85044-5399 


E-Mail  Address 


□  Please  send  me  my  Free  TooLink  monthly  updates.  (E-mail  required) 


Reliable,  Compatible  and  Cost  Effective  KVM  Solutions 


The  Technician's 
Choice  for  Reliability 

StarTech. corn's  StarView  KVM  Switches  provide  the  most  reliable  solution 
for  controlling  multiple  computers.  Advanced  features  such  as 
"hot-pluggability"  and  "anti-freeze"  technology  virtually  eliminate 
downtime.  Guaranteed  compatibility  with  Compaq,  HP  and  IBM 
servers/systems  make  implimentation  into  your  existing  network  a  breeze. 


Try  the  KVM  Planner  today! 

Visit  www.startech.com/KVMNW 


"TOT 


KVM  Planner 


Request  your  FREE 
KVM  Switch  Brochure  at: 


StarTech.com 


www.startech.com/KVMNW 
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Phone 


NWW1/02 


BUSINESS  REPLY  MAIL 

FIRST-CLASS  MAIL  PERMIT  NO  27  AURORA  OH 
POSTAGE  WILL  BE  PAID  BY  ADDRESSEE 

NETWORK  TECHNOLOGIES  INC 

1275  DANNER  DR 
AURORA  OH  44202-9928 
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Strong  Solutions  from  American  Network  Products 


II 
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: 
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When  it  comes  to  computer  racks  and  cabinets  you 
get  what  you  pay  for.  After  investing  thousands  of 
dollars  into  your  system  hardware  why  settle  for  a 
cheap  rack?  The  NetWorkCenter  is  designed  to 
give  you  maximum  strength  and  design  flexibility. 
Moderately  priced,  this  system  is  the  solution  you 
can  rely  on  for  years  to  come. 

VISIT  OUR  WEBSITE 
to  find  out  more  about  our  entire  line 
of  rack  solutions. 

AMERICAN  NETWORK  PRODUCTS 

For  more  information  call  508-867-3801  or  e-mail  us  at  amnetpro@aol.com 


www.networkcenter.com  NWW1/02 


I  am  a: 

□  Professional  Computer  User 

□  Intermediate  Computer  User 

□  Novice  Computer  User 

NWW1/02 


BUSINESS  REPLY  MAIL 

FIRST-CLASS  MAIL  PERMIT  NO.  2572  CLEARWATER  FL 
POSTAGE  WILL  BE  PAID  BY  ADDRESSEE 

SmartCertlfy  Direct 
A  SmartForce  Company 

PO  BOX  5779 

CLEARWATER  FL  33758-9718 


I  ii  Mil  iIIiIimIiIiIi  I  ii  I  ■lilii  lull  ■111111111111111 


NO  POSTAGE 
NECESSARY 
IF  MAILED 
IN  THE 

UNITED  STATES 


GET  A  FREE  Subscription! 


Apply  on-line  today  at 
www.nwwsubscribc.com/pb202 


Keep  ill  Morning! 
Inform  us  immediately  ot 

www.nwwsubscribe.com 


Get  A  FREE 


Atetworkl 


going  to  .,  still  a  tough  sell 


Subscription! 


A  SZ55.00 
Value! 


APPIY0H-1INE  TODAY  AT: 

vyww.nwwsubscribe.com/pb202 


Get  A  FREE 


tewgrWtoWi 


JSaB^afUfcMOO 

gomgto  ..  St*  a  tough  sell 


Subscription! 


A  s255.00 
Value! 


APPLY  ON-LINE  TODAY  AT: 

www.nwwsubscribe.com/pb202 


Get  A  FREE 


morkWnrifi, 

srasis 


Subscription! 


\  s255.00 
Value! 


APPLY  ON-LINE  TODAY  AT: 

www.nwwsubscribe.com/pb202 


Spread  the 
Word  to  Your 
Colleagues! 

Tear  off  a  card  above  and 
pass  it  to  a  fellow  Network 
IT  Executive  who  might 
want  a  FREE  Network  World 
subscription! 


The  premiere  designer  and  manufacturer 
of  modular  ergonomic  computer  support 
furniture,  enclosures  &  cabinets. 

Racking  Systems  •  Enclosures  •  19"  Rackmount  • 
Relay  Racks  •  Personal  Workstations  •  KVM 

2-61  Borden  Ave.  L.I.C,  NY  11101 

www.hergo.com 


There  Is  A  Better  Way  To  Troubleshoot 
&  Manage  Your  Network — Observer ® 


Quickly  Pinpoint, 
Pre-solve  and  Prevent 
Network  Problems 


<  Co<*PaVV'  _ _ 

.  a?*— - 


Observer — Identifies 
network  trouble  spots  and  costs 
thousands  less  than  expensive 
hardware-based  analyzers. 

Full  packet  capture  and  decode 

for  over  500  protocols,  including 
TCP/IP  (v4  &  v6),  NetBIOS/NetBEUI, 
XolP,  SNA,  SQL,  IPX/SPX,  Appletalk 
and  many,  many  more! 

Switched  mode  sees  all  ports  on  a  switch 
gathering  statistics  from  an  entire  switch  or 
capture/statistics  from  any  port(s) 

Long-term  network  trending  collects 
statistical  data  for  days,  weeks,  months, 
even  years 

Real-time  statistics  include  Top  Talkers, 
Bandwidth,  Protocol  Statistics,  and 
Efficiency  History 

Ethernet  (10/100/1000),  Token  Ring,  FDDI 

*  Windows *  98/Me/NT/2000/XP 
compatible 

•  Over  4,000  frame  types  recognized 


Expert  Observer — Includes  all  of  the 
features  of  Observer  plus  real-time  and 
post-capture  expert  event  identification 
and  analysis — new  SQL  and  Frame  Relay 
experts  add  to  the  many  other  protocols 
covered,  time  synchronization  technology, 
and  modeling  of  network  traffic. 

Observer  Suite — Provides  a  full 
complement  of  tools  that  includes  all 
of  the  features  of  Expert  Observer  plus 
SNMP  management,  RMON  console/ 
Probe  and  Web  reporting.  Includes  one 
remote  Probe. 

If  you  have  any  network  problems, 
find  out  the  cause  with  Observer, 
Expert  Observer,  or  Observer  Suite. 


NETWORK 

INSTRUMENTS 


Observer  ExPert  Observer 

$ags  Observer  Suite 

* 2895  *3995 


Call  800-526-7919  or  visit  us  online  for  a  full-featured  evaluation: 

www.networkinstruments.com 

US  (952)  932-9899  •  Fax  (952)  932-9545  •  UK  &  Europe  +44  (0)  1959  569880  •  Fax  +44  (0)  13E9  5698?  : 

©  2001  Network  Instruments,  LLC.  Observer,  "Network  Instruments"  and  the  “N  with  a  dot”  logo  are  registered  trade-  ::■* 
Network  Instruments,  LLC.  All  other  trademarks  are  property  of  their  respective  owners. 
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Server  Management 


UltraLink™ 

KVM  digital  remote  access 
over  Ethernet  or  modem 


Vista™ 

Low  cost  single-user  KVM  switch 
Supports  up  to  64  computers 


COI^BOL  IT 

SECuRiEL  IT  < 

MANAGE  IT  ^ 

FROM  ANYWHERE 


CrystalView™ 

Extends  your  KVM  station 
up  to  1 ,000  feet  away 
from  your  computer  using 
a  CAT-5  cable 


|/iew  Pro™ 

Isional  single-user  KVM  switch 
irts  up  to  256  computers 


Rose  Electronics  KVM  switches  allow  single  or  \ 
multiple  workstations  to  have  local  or  remote  access  to 
multiple  computers  located  in  server  rooms  or  on  the 
desktop. 

Rose  is  a  leading  KVM  switch  manufacii^f>ptt)  the 
most  complete  range  of  server  managerherit'^frpducts. 

A  KVM  industry  pioneer,  Rose  is  known  for  jts  • 
technically  superior  and  price  competitive  ]M:odudts:.>;% 

From  simple  access  to  complex  configurations, 
provides  easy  server  management  solutions. 

'i  •••- 

Call  ROSE  today. 


UltraMatrix™  X-series 
Enterprise  class  multi-user  KVM  switch 
4  -  250  KVM  stations  to 
1 ,000s  of  computers  or  servers. 


RackView™ 

Rack  mounted  1 U  or  2U  KVM  drawer 
with  optional  KVM  switch 


ELECTRONICS 


Rose  Electronics 

10707  Stancliff  Rd 
Houston,  Texas  77099 


USA  . CANADA . ENGLAND  .FRANCE 
GERMANY  .  BENELUX.  AUSTRALIA  .  SINGAPORE 


WWW.ROSE.COM 


SilentRunner  is  Turning  Network  Security  Inside-out 


OK  All  your  proprietary  data  is  locked  safe¬ 
ly  away  from  15-year-old  hackers.  Now  all  you 
need  to  worry  about  is  the  villain  who  really 
knows  your  business,  and  how  valuable  your 
information  actually  is...  the  insidious  insider. 

I  v  fortunately,  70%  of  network  fraud  and 
abuse  comes  from  within.  And  the  more  net¬ 
work  n  iiant  businesses  are,  the  more  vulnerable 
you  become  Protect  your  assets  with 
SilentRum  KT.  SlIcntRi  inner  provides  the  tools  to 
assess  risks,  prevent  misuse  and  abuse,  and  the 
network  forensics  to  track  down  even  the  most 
cunning  perpetrators. 


Discover  the  breakthrough  technology  that 
lets  you  out-fox  insidious 
insiders.  For  your  free  white 
paper,  “The  Insider  Threat,” 
visit  www.silentrunner.com 
or  call  800-842-2366  today. 


SilentRunner 

www.silentrunner.com 

849  International  Drive  •  Ltnthicum.  Md  21090  •  800842-2366 


RACK  MOUNT  TFT  DISPLAYS 

We  provide  the  solutions  for  your  rack  mount  display 
requirements  with  our  innovative  TFT  product  line. 


KEYBOARD,  TOUCHPAD  AND  TRACKBALL  OPTIONS 
1 U,  2U  AND  PANEL  MOUNTED  CONFIGURATIONS 
12.1”,  13.3”,  15”  AND  17"  TFT  DISPLAY  SIZES 

Contact  us  for  more  information.  \ 

www.recortec.com  1-800-729-7654  info@recortec  .com 

m  Proudly  manufactured  in  the  U.S.A.  by  | j 

RECORTEC,  INC. 

1620-A  Berryessa  Road  San  Jose,  Ca  95133  Tel:  (408)  928-1480  Fax:(408)729-3661 
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Converters 


Cable 
Assemblies 


An  Important  Part  Of  The  Network 


J  Bypass  j 
Switch 


Simulation'  LAN  \  Test 
Tost  Box  Equipment  I  Equipment  p 
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y°ur  NETWORK 


GigaBit  Fault  Tolerant-Redundant  Security  Port  Selector 

Net  Optics'  Fiber  GigaBit  Fault  Tolerant  Port  Selector 
detects  fault  line  automatically  to  prevent 
your  network  traffic  from  stopping. 

This  product  is  a  MUST  for  ISP  centers, 
and  central  offices  with  critical 
data.  Works  well  with  all  GigaBit 

Servers,  Switches  brand  names.  . .  .  _  .  ,  _  _  ,  , 

Network  Redundancy!  your  N  ETWORK 


*-*■  visit:  www.netoptics.com/net-96260.html 


GigaBit  Copper  to  SX,  LX  or  ZX  Fiber  Converters 

Net  Optics'  Gigabit  Copper  to  Fiber  Converter  allows 
network  managers  to  migrate  to  GigaBit  Ethernet 
in  a  cost-effective  manner. 

Simply  plug-in  the  Cables. 


visit:  www.netoptics.com/sx-tx-converter.html 


GigaBit  ZX,  LX  to  SX  Media  Converter 

Net  Optics'  Fiber  Optic  Mode  Converter  is  used  to 
connect  two  devices  operating  with  GigaBit  multimode 
LX  fiber  to  SX  fiber. 

The  fiber  converter 
provides  transparent 
conversion  of  optical 
signals. 


'-+•  visit:  www.netoptics.com/converter-gig.html 


Fiberoptics  Cable  Assemblies 

The  Net  Optics'  total  solutions  approach  can  provide  you 
with  any  type  of  fiberoptic  cable  assembly  you  need, 
from  LC,  MTRJ,  SC,  MIC,  FC  or  Escon  patch  cords  for 
your  ATM,  Gigabit  and  any  other  network. 

Also  available: 

LC,  SC,  MT-RJ  fiberoptic  Loopbacks. 

'■+•  visit:  www.netoptics.com/2.html 


Network  Monitoring  Accessories 

In  some  countries  ISP's  must  beTAPable...  is  the  new  Law! 


GigaBit  SX,  LX  or  ZX,  ATM,  DS3,  T1,  Copper  and  Fiber  Taps 

These  Splitter  Taps  have  capabilities  that  will  allow  the 
networks  to  operate  at  a  continuous  flow  while  the  tap  is 
non-operational,  thus  maintaining  network  integrity.  This 
enables  you  to  monitor  the  network  without  disconnecting 
any  one  link! 

The  Fiber  Splitter  Tap  has  passive-link  integrity  that  is 
maintained  whether  the  device  is  on  or  off. 

Copper  Gigabit  to  Fiber  Taps  feature  two  Power 
Supplies  which  are  load  sharing.  If  either  unit  fails, 
the  remaining  power  supply  comes  up  to  full  power 
and  takes  over  the  additional  load. 

Compatible  with  all  analyzer  manufacturers  including: 

Network  Associates'  Sniffer®,  Agilent's  Internet  Advisor  and 
Cisco's  SwitchProbe  products. 

'-►visit:  www.netoptics.com/11.html 


Net  Optics'  GigaBit  TX  to  SX  Tap  is  the  market’s  first 
copper  to  fiber  tap! 


GigaBit  Fiber  Tap 


Copper  100BaseT  Tap 


6  Station  Tap 


Troubleshoot 

NETWORK 

_  Problems 


Tap  Diagnostic 


i  Z  ro  1 0ptics"1 

www.netoptics.com 


Bright  ideas. .  -  Built  for  sjpeedf 

Note:  Sniffer®  is  a  registered  trademark  of  Network  Associates  Inc. 


Net  Optics,  Inc.  •  1230-AOId  Mountain  View-Alviso  Road  •  Sunnyvale,  CA  94089-2237  •  USA  Tel:  +1  (408)737-7777  •  Fax:  +1(408)745-7719  •  world@netoptics.com 


PM 


The  Hub  of  the  Network  Buy 


Internal 

UPS 


Microphone 
for  Sound 
Monitoring 


Embedded 

Web 

Server 


Sends 

E-Mail 


Power 

Outage 


Power 

Control 

Interface 


Ethernet 

Port 


Internal  Voice, 
Modem 
&  Pager  Port 


8  RJ-45  Sensor  Inputs 

(Temperature,  Humidity, 
Water,  Motion,  Power, 
Smoke/Fire) 


Sends 

SNMP 

Messages 


Monitors 

64 

IP  addresses 


BE  NOTIFIED  BEFORE  CRITICAL  EVENTS  TURN  INTO  DISASTER! 


•  Eight  environment  inputs 

•  Power  sensing 

•  Monitors  64  IP  addresses 

•  Send  alerts  to  64  people 

•  8  methods  of  contact 

•  Calendar  scheduling 

•  Expands  to  256  sensors 

•  Remote  power  control 

•  Optional  camera 


The  Sensaphone  IMS-4000  Infrastructure 
Monitoring  System  monitors  critical  environ¬ 
mental  and  network  elements  in  your  server 
room,  data  center,  or  telecomm  installation  and 
reports  to  you  instantly  when  events  threaten 
your  infrastructure.  The  IMS-4000  keeps  watch 
so  you  don't  have  to.  See  these  features  and 
more  on  the  web  at  www.ims-4000.com 


e 

Phonetics,  Inc. 

Tel:  877-373-2700 

901  Tryens  Road 

www.ims-4000.com 

Aston,  PA  19014 

Seeking  Solutions  ...NTI  Has  The  Answers! 


BREAKTHROUGH 
CAT5  KVM 
EXTENDER 


“I  need  to  extend  control  & 
protect  my  computers  from 
hazardous  conditions.” 


■  Allows  one  keyboard, 
monitor  &  mouse  to  be 
placed  up  to  575  feet 
from  the  computer  or 
NTI  KVM  switch  using 
in-house  Cat5  phone 
wiring. 


NTI  | 

T 

P  r 

1 

NTISs 
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ST-C5-KVM  (Local  and  Remote  Unit) 

UNIVERSAL  CAT5 


■  Available  in  both  KVM 
and  Video  Only  models. 

■  Compatible  with  PC, 
SUN  &  MAC  computers 
as  well  as  all  NTI  KVM 
switches. 

■  Crisp  &  clear 
1280x1024  resolution. 


BUY  ONLINE  at  www.nti1.com 


Phone:  800-742-8324 


Email:  sales@nti1.com 


1275  Danner  Drive  •  Aurora,  OH  44202 
330-562-7070  •  FAX:  330-562-1999 


CAT5  KVM  SOLUTIONS 


YOUR  AMERITECH  AUTHORIZED  DISTRIBUTOR 


The  future  will  take 
your  business  places 
you've  never  dreamed* 
We  can  help  you  get 
there  faster* 


Your  Ameritech  Authorized  Distributor  can  help  your  business 
communications  do  so  much  more.  Ameritech  Authorized  Distributors 
offer  a  full  portfolio  of  services  —  services  that  can  increase  the  speed 
and  carrying  capacity  of  your  network.  So  you  can  enhance  employee 
productivity,  cut  costs  and  explore  new  business  opportunities. 

Get  a  jump  on  tomorrow. 

Call  (734)  995-1233  today. 


AmeriNef 


©1999  Amentodh 
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EQUINOX 

PCI  Multi-modem  Adapters 

With  a  price  per  port  and  performance  that  can’t  be  beat 
Equinox  PCI  Multi-modem  Adapters  deliver  flexible  and 
cost-effective  dial-access  connectivity.  ? 

Compare  for  yourself! 

Equinox  PCI  Multi-modem  Adapters 

provide  a  44%  to  36%  savings 

over  the  leading  competitors  .  V 

of  similar  products 


Our  PCI  Multi-modem  Adapters  ^ 
are  available  in  4  and  8-port  models 
and  are  scalable  to  32  ports  per  server. 


SST-MM8P  PCI 


Equinox  Multi-modem  Adapters 
install  in  minutes  and  require  no 
interrupts.  They  are  compatible 
with  most  popular  operating 
systems  and  are  easily  deployed 
highly  manageable  and  available 
at  a  price/performance  point 
that  is  truly  unmatched. 


Try  before  you  buy! 

Call  Today!  800-275-3500,  ext.  615 
or  +1-954-746-9000,  ext.  399 
for  your  FREE  30-day  evaluation. 
Email:  sales@equinox.com 


an  Avocent  Company 


DON'T  JUST  VP 


FatPipe  it! 


WITH  MULTI-PATH  VPN 


CORPORATE  OFFICE 


FATPIPE  MPVPN 


Multi-Path  VPN  takes  any  VPN  &  makes  it  9  times  more  secure 
and  3  times  faster,  reliable  and  redundant 


FILE  SERVERS 


ANY  VPN 


FatPipe  Networks'  Multi-Path  VPN  (MPVPN) 
turns  any  VPN  into  a  Multi-Path  VPN 

•  No  BGP  programming  or  new  hardware  at  the  ISP 

•  Dynamic  bi-directional  load  balancing  of  traffic 

•  3  times  more  speed,  reliability,  and  redundancy 

•  Works  with  Ti,  T3,  Ei,  E3,  DSL,  and  Wireless 

•  Works  over  multiple  ISPs  and  backbones 

•  Reliability  for  hosting  web  servers 

•  Works  with  all  IPSEC  VPNs 

•  Host  multi-homed  servers 

•  9  times  more  secure 


ANY  VPN 
FILE  SERVERS 


ISP  1,  2,  &  3 


ISP  1,  2,  &  3 


Patented  and  Multiple  Patents  Pending 


FATPIPE  MPVPN 


FatPipe  (Networks 
I  nfo(a)fatpi  peinc.com 
Tel:8oo. 724. 8521 
Fax:  801.281.0317 


BRANCH  OFFICE 


The  Hub  of  the  Network  Buy 


i  ItairkWorkTs  '■ 
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Authorized  Reseller 

Buy  Sell  Lease  Repair 

New  Refurbished  Used 

Routers  Nortel  DSU/CSUs 

Switches  Memory  3Com 

Hubs  ISDN 

1  877  231  2451 


PRODUCTS 


www.wdpi.com 

Email:  cisco6@wdpi.com 


Cisco  Sistems 


Reseller 


Direct  Response  Advertising 
Sales  Territory  Map 


Cara  Peters,  Account  Manager,  California  &  Hawaii 
Tel:  800.622.1108  ext.  6505  Email:  cpeters@nww.com 


Karima  Zannotti,  Sr.  Account  Manager,  Central  US/Pacific  Northwest 
Tel:  800.622.1108  ext.  6469  Email:  kzannotti@nww.com 


Richard  Black,  Director,  New  England,  PA,  NY,  NJ 
Tel:  800.622.1108  ext.  6596  Email:  rblack@nww.com 


Amie  Gaston,  Account  Executive,  Mid-Atlantic/Southeast/Canada 
Tel:  800.622.1108  ext.6408  Email:  agaston@nww.com 


Enku  Gubaie,  Sr.  Account  Manager/Special  Projects  Leader 
Tel:  800.622.1108  ext.  6465  Email:  egubaie@nww.com 


Remote  Network  Management  Solutions 

Access  Your  Network  Equipment  from  Anywhere 


Telnet  and  Dial-Up  Console/AUX  Port  Switch 

Cost  Effective  Terminal  Server  Alternative 


10Base-T  Ethernet  Interface 


m* 

AC  or -48V  DC  Power 


19”  Rack  Mounted 


RS232  Ports 


Console  Management  Switch  (CMS)  ) 


■■■ 


•  8, 16  or  32  RS232  DB-9  Serial  Ports 

•  Simultaneous  Telnet  Sessions 

•  Non-Connect  Port  Buffering  -  32K 

•  IP  Security  Features 

•  Modem  Auto-Setup  Command 
Strings  (User  Definable) 

•  NEBS  3  Approved  •igjOTE/OMsmira 


SUN 

00N80U 


LINUX 

CONSOLE 


ROUTER 

CONSOLE 


i  i  r 

CMS-16 

=zi 

T 

(Sr-Q— )- 

MODEM 

LOCAL  TERMNAL 


ruu 


ifb  o 

JLBD 


Telnet  and  Dial-Up  Network  Power  Switch 

Reboot  Locked-up  Equipment 


Individually  Controlled  Outlet  Plugs  (8) 


lOBase-T  Ethernet 
Interface 


19”  Rack  Brackets 
Allow  Front,  Back, 
or  Center  Mounting 


Dual  15  Amp 
Power  Circuits 


Modem  Port  for 
Out-of-Band  Management 


r 

Local  RS232  Console  Port 


(  Network  Power  Switch  (NPS)  ) 

8  Individual  Outlets  •  Outlet-Specific  Password  Security 

On/Off/Reboot  Switching  •  Network  Security  Features 

Integral  1 0Base-T  Interface  •  1 1 5- VAC  (230-VAC  available) 
Co-Location  Features  •  Power-Up  Sequencing 


vmw.wti.com 


(800)  854-7226 


western  telematic  incorporated 

5  Sterling  •  Irvine  •  California  •  92618-2517 


Keeping  the  Net.. .Working! 
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Netfast  Communications  Inc.,  56-29  56th  Drive,  Maspeth,  NY  1 1378  USA 
Phone:  1-888-892-4726  or  718-894-7500  Fax:718-894-1573 
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►  CISCO  ►  Juniper  ►  Lucent  >•  Nortel  ►  Marconi 

www.digitalwarehouse.com  ►  Foundry  >•  Adtron 

WAR1HOUS1  .  Extreme  ►  Quick  Eagle 


Information  Superhighway  Discount  Sources 


Save  big  on  new/used:  >  Routers  ►  Gigabit/FE/ATM  Switches 
►Access  Servers  >•  Optical  Networking  >•  Wireless  BUY/SELL/RENT 


Increase  Your  Exposure 
with  NetworkWorld’s 
Response  Cards! 


Next  Issue:  March  25 
Ad  Close:  February  4 


Call  your  sales 
rep  for  details  on  this  new 
advertising  opportunity. 


See 

the  insert  in 
this  week's  issue 
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800.45 

VO  C«»titien  Drive .  Suite  lit 

1.3407 

Sent*  Barbara.  CA  93117 

Routers 
Switches 
Interface  Modules 
Access  Servers 
Accessories 

www. network  hardware. com 

BUY  ONLINE 


NETWORK  HARDWARE  RESALE 


Get  More  lor  Today's  Budget! 

Contact  BIZI 
to  SAVE  up  to  80% 


•  50-80%  Savings  off  Retail  List  Prices 

•  1 20-Day  Warranty 

•  100%  30  Day-Money  Back  Guarantee 

•  Large  Inventory,  Same  day  Shipping 

•  Supplying  Quality  Networking  Products 
for  Over  10  Years  with  In-House  Technical  Support 

Request  a  Quote  on-line  at: 

http://www.bizint.com  or  info@bizint.com 

(877)  438-2494 

or  (315)  458-9606  fax:  (315)  458-9493 


We  Buy,  Sell,  Trade  and  Lease... 


Your  global  partners  in  new  &  quality 
pre-owned  networking  equipment 


CISCO,  BAY/NORTEL,  3COM,  CABLETRON,  EXTREME,  FOUNDRY,  JUNIPER 


jTTfi)  70  sjU'J 

Networking 
Products 
and  Services 


Over  170,000  qualified 
subscribers  of  Network 
World  are  ready  to  buy. 

Call  today  to  place  your 
ad  in  the  Marketplace! 
1-800-622-1108 
ext.  6465 


> 
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BNETSYS  Inc. 

(800)  BNETSYS 
www.bnetsys.net 
Instructor  led  &  online  Cisco 
certification  training  @  no  charge 
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PMG  NetAnalyst 

(800)  645-8486 
www.NetworkTraining.com 
Network  Forensic  Analysis  and 
Security  Training  and  Services 

Learnkey  Inc. 

(800)  865-0165 
www.learnkey.com 
Self-paced  online  CD  network 
certification  developer  bus/apps 


To  Place  Your 
Listing  Here 
Call  Enku  Gubaie 
at  1-800-622-1108 


Contact  these  companies 
I  today  to  help  you  with  your 
training  needs! 


* Your  Network  Technology  Source' 

Toll  Free:  877-868-6638 
www.MTMnet.com 
sales@MTMnet.com 


For  more  information 
on  advertising  in 
Network  World’s 
Marketplace  contact: 

Enku  Gubaie, 

800-622-1108  ext.  6465, 
egubaie@nww.com 


WRCA.NET 
NEW  «^»  USED 

WwVhMd.  Plotter  <*  UlfmrV.  HanW.  ilncalMl 

AUTHORIZED  RESELLER 
Access/Routers/Switches 
Cisco  Livingston  Ascend 
3Com  US  Robotics  Kentrox 
Adtran  BayNetworks  Xyplex 
Computone  Digital  Link 
Modems  /  DSU  /  Muxes 
IBM  UDS  Codex  Hayes  GDC 
Micom  Microcom  Paradyne 
ATT  MultiTech  Penril 
Racal  Telebit  Zoom 

WE  BUY  AND  SELL 
www.wrca.net 

800-699-9722 


N62RTELnetworks 
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BROWSING  THE  AUCTIONS? 
Consider  What  You  Get: 


National  LAN  Exchange  Auctions 


•  Nortel  Service  Contracts 

•  Nortel  Service  Renewals 

•  Next-Day  Hardware 
Replacement 

•  Free  Technical  Support 

•  One  Year  Warranties 

•  New  and  Used  Equipment 

•  Hundreds  of  Pieces 
in  Stock 

•  Design/Install  Services 

•  Fast  Overnight  Delivery 


•  No  Service  Contracts 

•  No  Service  Renewals 

•  No  Replacements, 

No  Guarantees 

•  No  Support 

•  No  Warranties 

•  Who  Knows? 

•  Sometimes  Available, 
Sometimes  Not 

•  No  Services 

•  Inconsistent  Delivery 


Make  the  Smart  Choice 


www.NLE.com 
New/Used  •  Buy/Sell 
National  LAN  Exchange 


888-8LANWAN 

(888-852-6926) 
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IT  CAREERS 


BRAINSTORM  GROUP  & 
GIGA  INFORMATION  GROUP® 


End-to-End  Integration 
Strategies  &  Solutions 


2002  Event  Schedule 


'  Chicago  -  March  25-27 

•  New  York  -  Sept.  23-25 

•  San  Francisco  -  Nov.  4-6 

Request  a  Brochure  Online  &  Be  Entered 
to  Win  a  3-Day  Pass  (a  $1403  value)! 


B.usiness . 

(§)'  integration '■ 

CONFERENCE  SERIES 

The  eBusiness  Integration  Conference 
Series  is  the  leading  forum  specifically 
designed  to  provide  business  and 
IT  leaders  with  solutions  to  the  full 
spectrum  of  e-business  integration 
challenges. 

Featuring  leading  analysts,  authors 
and  end  user  case  studies,  this 
series  details  the  business  driven 
strategies,  the  latest  technological 
advancements,  proven  “Best  of 
Breed”  solutions  and  trends  in 
e-business  integration. 

Join  us  for  actionable  advice, 
invaluable  networking  opportunities  and 
practical  solutions  to  your  most  pressing 
e-business  integration  challenges. 

Conference  Co-Chairmen 


Ken  Vollmer 

Research  Director 
B2B  Integration  Strategies 
Giga  Information  Group 

Produced  by 


William  M.  Ulrich 

President 

Tactical  Strategy  Group,  Inc. 


Giga  Information  Group* 

Technology  advice. 
Business  results. 


www.brainstorm-groiip.com  T:  508*393-3266 


Independent,  Contract  Sales  Representatives 


It’s  like  having 


our  own  Business 


...only  better. 


This  is  your  opportunity 
to  use  your  executive 
level  contacts, 
aggressive,  entrepreneurial 
spirit  and  sales  presentation 
experience  to  build  a 
lucrative  business.  As  a  top 
20  IT  services  company, 
we're  ready  to  contract 
with  you  to  earn  high 
commissions  for  selling 
our  best-in-breed  products 
and  services  to  your  client 
base.  The  expanse  of 
our  software  products 
and  capabilities  in  human 
capital  management,  web 
development,  staffing  and 
technical  instruction 
programs  will  excite  you 
to  hit-  the-  ground  running 
after  lucrative  sales  of 
$1-30+  million. 


To  excel  on  this  level,  you  must  embody  the 
entrepreneurial  spirit  and  thrive  when  given 
ample  leads,  support  and  complete 
independence  to  aggressively  pursue  your 
potential  clients.  Typically,  qualified 
candidates  will  be  retired  executives, 
successful  sales  professionals  or  any  driven 
individual  with  a  great  rolodex  filled  with 
high  level  decision  makers  regarding  the 
purchase  of  IT  products  and  services. 


If  qualified,  you'll  have  the  resources  and 
support  of  a  world  class,  Top  20  IT  Services 
organization  at  your  disposal.  These  resources 
will  include  sophisticated  marketing  and 
public  relations  materials,  an  efficient  lead 
clearing  house  and  skilled  technical  support. 
This  commission  only  relationship  will  allow 
you  to  build  your  own  business  and  you  will 
be  reimbursed  for  your  expenses. 


For  immediate  consideration,  send  your 
resume  to  our  recruitment  advertising 


agency: 


fericson@bsa.com 


EOE. 


nobody  gets  It  like  Die 


The  tech  qatie  has  chancec 
How  you  Wifi,  hasr  ’  t 


The  tech  game  can  change  all  it 
wants  to,  but  savvy  technology 
professionals  still  know  how  to  win 
with  Dice.com.  Show  change  who's 
the  boss.  Visit  Dice.com  today. 


©2002  Dice  com 


Database/Systems  Administrator: 
Manage  &  administer  Windows 
2000  Server  &  SQL  Server  2000 
database  &  applications.  Help 
establish  &  manage  database  & 
system  change  mgmt.  procedures. 
Assist  w/architect  overall  data 
structure.  Provide  performance 
tuning  &  data  conversion  service. 
Manage  scalability  &  system 
upgrade  process.  3  yrs  exp.  in 
the  position  offered  in  a  database 
or  systems  administration  position 
managing  mission  critical  data¬ 
bases  environment  w/large  user 
base.  3  yrs  exp.  must  include 
exp.  in  Microsoft  IIS  Server, 
Microsoft  Digital  Internet  Archi¬ 
tecture,  Microsoft  Clustering 
Technology,  Microsoft  Biztalk 
Server,  Microsoft  Message 
Queue.  MCDBA  required. 
Resume  to  Ash  Momin  Supna 
Technologies  Corp.,  4438 
Lyngate  Dr.,  Lilburn,  GA  30047. 


"We  have  multiple  openings  for 
IT  professionals  with  industry 
exp.  (various  skills  combination 
reqd.)  in  C,  C++  ,  HP-UX, 
Progress  7.3E,  Astea,  SAP  R/3, 
SQL  Server  7,  VJ++,  HP  9000, 
Oracle  7.x/8,  VB,  VB  Script, 
Informix  4  GL/7.X,  Informix 
Dynamic  4GL,  Baan,  MFG  Pro, 
Informix  Online,  SQL  Base,  SCO 
Unix,  Informix  SE.  etc.  Some 
positions  require  MS  or  equiv. 
CS,  Engg.,  Math.,  Bus.  Admin. or 
rel.  field.  Others  require  BS  or 
equiv.  in  any  of  the  above.  Pay 
matching  with  exp.  Foreign  educ. 
equiv  &/ or  combination  of  educ/ 
exp.  accepted.  Travel/relocation 
reqd.  Res.  &  salary  expectations 
to  HR  Dept.,  105  Nobel  Ct., 
Alpharetta,  GA  30005." 


♦ 


DTI,  a  software  consulting  co. 
in  Fremont.  CA  seeks  Software 
Consultants  at  all  levels  to 
perform  JD  Edwards  implemen¬ 
tations  and  EAI  integration. 
Requires  travel. 

Send  resume:  Careers,  DTI, 
47001  Benicia  St.,  Fremont.  CA 
94538.  Fax  (510)  353-3706  or 
email:  careers@dtius.com 


"We  seek  professionals  with 
industry  exp.  for  scoping,  planning, 
etc.  of  solutions/enhancements 
to  web  enabled  SAP  R/3  appls.; 
manage  HRMS  life  cycles  &  high 
level  strategic  analysis,  desrgn, 
etc.  of  HR  Service  delivery 
supporting  HR  transition  from 
transactional  process  flow  to 
business  flow,  etc.  Hands  on 
experience  of  web  enabling  HR 
Module  using  Web  Studio,  ITS, 
CATS.  ESS  reqd.  Pay  matching 
exp.  Foreign  educ.  equiv  &/ 
or  combination  of  educ/exp. 
accepted.  Tavel/relocation  reqd. 
Resume  to  Global  Resources 
Mgmt.,  Inc,  3355  NE  Expwy,  Ste. 
205,  Atlanta,  GA  30341 ." 


CBOE 

CHICAGO  BOARD  OPTIOHS  EXCHANGE 


Chicago  Board  Options  Exchange 
is  the  world’s  largest  options 
exchange.  To  grow  our  business 
and  increase  our  technical  edge, 
we  develop  and  implement  the 
latest  technology.  We  currently 
have  the  following  opportunities: 

•  Engineer 

•  Software  and  Hardware 
Engineer 

•  Sr.  Programmer  Analyst  and 
Programmer  Analysts 

As  part  of  the  CBOE,  you  will 
enjoy  a  competitive  salary  and 
excellent  benefits.  For  further 
consideration,  please  send  your 
resume,  via  fax  or  e-mail  indicating 
the  job  title  in  the  subject  line. 
Resumes  may  be  also  be 
submitted  via  mail  to  CBOE, 
Attn:  Human  Resources,  400 
S.  LaSalle,  Chicago,  IL  60605. 
For  further  information  regarding 
these  opportunities  as  well 
as  other  opportunities,  please 
visit  our  website  at  http:// 
www.cboe.com.  E-mail: 

j  o  b  s  2  0  0  2 

©cboe.com  or  fax:  (312)  786- 
7808.  Principals  only,  please. 
CBOE  is  an  equal  opportunity 


Reading  someone  else's 
copy  of  Network  World? 


Apply  for  your  own  FREE  subscription  go  to 

www.nwwsubscribe.com/pa 

and  subscribe  today! 

Week  after  week  NW  gives  you  late  breaking  news  and  in- 
depth  insights  on  infrastructure,  carriers  and  ISPs,  enterprise 
applications,  technology  updates  and  management  strategies. 

Plus... 

•  Enterprise  level  product  testing 

•  Product  Buyers  Guides 

•  Management  surveys 

•  Signature  Series  Special  Issues 

Apply  for  your  FREE  Subscription  Today 

www.nwwsubscribe.com/pa 
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careers.com 


IT  CAREERS 


© 


careers 


Programmer  Analyst  to  analyze, 
research,  design  and  develop 
scientific  computer  applications 
using  statistical  software  such  as 
SAS,  SPSS  and  languages  such 
as  C,  C++  and  Oracle  Databases 
with  PL/SQL  under  Unix,  VAX/ 
VMS  platforms.  Gather  user  and 
technical  specification  to  maintain 
scientific  applications.  Require 
BS  in  sciences,  computer  science 
or  engineering  (any  branch)  and 
2  years  of  experience  in  software 
development.  Competitive  salary. 
Some  travel/relocation  required. 
Send  Resumes  to:  UNILINX, 
4625  Alexander  Drive,  Suite 
110,  Alpharetta.  GA  30022. 


You  can 
find  a 
better 

JOB 

with  one 
hand  tied 
behind 
your  back. 


Just  point  your 
mouse  to  the 
world’s  best 
IT  careers  site. 


Brought  to 
you  by 

Computerworld, 
Info  World  and 
Network  World. 


Find  out  more. 

Call  your 
ITcareers  Sales 
Representative 
or  Janis  Crowley, 
1-800-762-2977 


Where  the  best 
get  better 


CC  Phila.  Co.  seeks  a  Software 

Engr./ETL  Specialist.  BS  in  Engr. 
req,  along  with  min  5  yrs,  exp.  in 
software  dev.  expert  knowl.  in 
Data  Warehousing,  SQL,  MS 
Access,  SQL  Server,  Oracle 

RDBMS,  relational  &  dimensional 
data  concepts.  Win  NT,  exp.  with 
ETL,  query  &  analys.  tools  such 
as  Cognos  DecisionStream, 
Transformer,  Impromptu  &  Power 
play.  Send  resumes  to:  Box 
58034,  Phila,  PA  19102,  Attn: 

Dave  Conrad.  EOE/AA. 

Jr.  Programmer.  Assist  in  design 

&  dev.  of  s/w  sys.  inc.  functional 

&  tech,  specs.  Conduct  needs 

analysis.  Assist  in  developing 

sys.  procedures,  docs,  coding, 

&  testing  progs.  Req.:  BS  in 

Computer  Eng.  or  Computer 

Sci.  40-hr  wk.  Job/Interview  Site: 

Diamond  Bar,  CA.  Send  resume 

to  MTSI,  Inc.  P.O.  Box  #207, 

1142  S.  Diamond  Bar  Blvd., 

Diamond  Bar,  CA  91765. 

Computer  Professional  needed 
w/exp  in:  Oracle  Tools,  Oracle 
enterprise  Manager,  Network 
Manager,  Developer  Suite,  Export/ 
Import,  Oracle  Application  Server, 
Microsoft  IIS,  RMAN,  SQL*Plus, 
ERWIN,  SQL'Net,  PL/SQL,  SQL 
■Navigator,  SQL'Loader,  C,  C++, 
Java,  Javascript,  PB,  COBOL, 
CICS,  DB2,  VSAM,  UNIX 
Administration,  Sun-Solaris  Ad¬ 
ministration,  MS  Windows/NT. 
Apply  to:  Prosoft  Consultancy 
Services,  Inc.,  15310  Amberly 
Dr,  Suite  250-12,  Tampa,  FL 
33647.  No  in  person  resumes/ 
interviews,  only  respond  by  mail 
or  e-mail. 

Software  Engineers 

Automated  Power  Exchange, 
located  in  Santa  Clara  is  seeking 
Software  Engineers  possessing 
MS/BS  or  eqiv.  and/or  relevant 
work  exp.  Work  exp.  with 
RDBMS  +  SQL,  MS  SQL  Server 
and  one  or  more  of  the  following: 
Javascript,  VBScript,  ASP,  VB 
and  XML.  Exp.  developing  com¬ 
mercial  applications  and  dealing 
with  settlements  in  the  power 
industry  desired.  Must  be  willing 
to  travel  and  relocate  as  required 
in  the  U.S.  Mail  resumes  to: 
Automated  Power  Exchange, 
c/o  HR,  5201  Great  America 
Parkway,  Suite  522,  Santa  Clara, 
CA  95054. 

Network  Administrator  needed 

for  Miami  Beach  computer  and 
electronic  sales  co.  to  monitor 

data  communications  network 

to  ensure  that  the  network  is 

available  to  all  system  users.  Min 
req.  2  yrs  exp.  Fax  resumes 
to  Sound  Connection  and 

Distributors,  Inc.  (305)  538-0881 . 

Junior  Programmer.  Assist  pro¬ 
grammers  in  developing  finance 

and  accounting  software  with  the 

use  of  database  and  spread¬ 
sheet  programming.  Requires 

a  B.S.  Computer  Science/Com¬ 
puter  Eng.  or  related  field.  40 

hour  work  week.  Send  resumes 

to  eMachines,  Inc.  14350  Myford 

Road,  Bldg.  100,  Irvine,  CA 

92606. 

Computer  Graphics  Designer  in 

NYC.  Masters  in  Communication 

Arts  or  related  with  concentration 

in  Computer  Graphics  or  related. 

Min.  1  yr.  exp:  designing  3D  ani¬ 
mated  moving  graphics  for  web 
pages;  maintenance  of  web 

graphics;  Access;  Photoshop 
5.0,  HTML,  DHTML,  JavaScript, 

HTML/Graphic  editors;  3D  design; 

40  hrs/wk  M-Fri  9-5.  Send  resume 

to:  Job  8,  P.O.  Box  5275,  New 

York,  NY  10185-5275. 

COMPUTER  APPLICATIONS 

ENGINEER.  Design,  code  &  test 

projects  in  client-server  tech., 

using  VC++,  VB,  Java,  Oracle, 

ASP,  SQL  Server  &  Visio.  Doc.  & 

manage  projects.  Req.:  Bach,  in 

Comp.  Science  Engr.  or  Elec¬ 
tronics/Electrical  Engr.  40-hr  wk. 

Job/lntvw  Site:  L.A.,  CA.  Send 

resume  to  Vikmere  Software. 

3723  Watseka  Ave.,  #9,  Los 

Angeles,  CA  90034. 

Computer  Systems  Engineer 

needed  for  Miami  Architecture 

co.  to  analyze  data  requirement 
and  plan  data  processing  system 
for  projected  workloads.  Min 
req.  4  yrs  exp.  Send  resumes  to 
Architectural  Design  Consortium, 
Inc.  P.O.  Box  370546  Miami, 

Florida  331 37. 

SOFTWARE  ENGINEERS:  Re¬ 
sponsible  for  software  integration 
and  external  interface  develop¬ 
ment.  Use  combination  of  Oracle 
PL-SQL,  CASE  tools  and  Peo- 
pleSoft  under  Oracle  8.x  envi¬ 
ronment  to  develop,  create, 
modify  and  maintain  application 
software  and/or  utility  modules 
for  DoD  HRMS  application. 
64K-72K(F-T;  40hr/wk);  New 
Orleans,  LA;  B.S. Computer 
Science  (or  equivalency);  4  yrs 
experience  or  related  experience 
in  ERP  package  customization. 

Contact:  Kenneth  Burkhalter 
personnel  @  otisincl  .net 

Tel.:  (985)781-3892 

where  the  best  get  better 

1-800-762-2977 


JAK  International  Corp.,  is  a 
diversified  trading  firm  with 
operations  in  the  U.S.  and  over¬ 
seas.  Our  company  currently 
has  openings  for  the  following: 

Business  Integration  Analysts: 
Analyze  business  intelligence 
requirements  of  client  users  to 
automate  processing  in  the 
context  of  financial  reporting, 
supply  chain  integration,  and 
e-commerce  applications.  Inter¬ 
face  with  programmers  and  DBA 
in  design  and  implementation 
of  software  solutions.  Prepare 
technical  reports  for  detailed 
documentation  of  software 
change  management  procedures. 
Use  relational  databases  including 
Oracle  and  DB2.  Engage  in 
project  management,  business 
process  re-engineering,  and 
inter-company  electronic  data 
transactions  using  knowledge  of 
mainframe,  client-server,  and 
web-based  environments. 

Need  Master's  degree  in 
Computer  Science  or  Business 
Administration.  Need  1  +  years  of 
experience.  Send  your  resume 
to:  VP  Operations,  7322  S.W. 
Frwy.,  Suite  788,  Houston,  Texas 
77074  or  send  via  e-mail  to: 
careers@jakintl.com 


DATABASE  MANAGER 
Davenport  University  is  in  search 
of  a  highly  qualified  Database 
Manager.  Responsibilities  include 
operation  and  maintenance  for 
the  library  automation  system 
including  software  and  hardware 
upgrades;  design,  development 
and  maintenance  of  University 
web  page;  coordinate  and 
implement  systems'  security; 
and  maintenance  of  remote 
online  access  to  the  library 
automation  system  catalog,  the 
online  resource  databases  and 
network  access  to  the  library 
automation  system  databases 
utilizing  NT/Windows  2000,  Sun 
hardware  and  Sun  Solaris  UNIX 
operating  system  5.6,  Sun 
Solstice  disc  suite,  Sybase,  and 
Sequel  Server  systems. 
Candidates  must  have  a  Bachelor 
of  Science  degree  in  Computer 
Science  or  Business  Adminis¬ 
tration  with  coursework  in 
computer  information  systems. 
Candidates  must  also  have 
permanent  authority  to  work  in 
the  United  States. 

Send  resumes  to  Human 
Resources,  Davenport  Universi¬ 
ty,  415  East  Fulton,  Grand 
Rapids,  Ml  49503. 


Software  Development  Engineer 
-  Collins  &  Aikman  is  seeking  in¬ 
dividuals  with  specialized  skills 
in  Graphical  User  Interface  (GUI) 
software  development  for  the 
position  of  Software  Development 
Engineer.  A  Master's  degree  in 
engineering,  computer  science 
or  related  field  is  required  for  this 
position,  as  well  as  one  year 
of  experience  developing  GUI 
software  features  using  X-Motif 
and  Java  programming  languages. 
Fax  or  mail  resumes  to:  Attn: 
Director,  Global  Acoustic  CAE 
Technology,  Collins  &  Aikman 
Corporation,  47785  West  Anchor 
Court,  Plymouth,  Ml  48170-2456. 
Tel:  734-207-7302;  Fax:  734-354- 
2220;  Email:  satha.raveendra 
©colaik.com 


♦ 


Sr.  Systems  Engineer.  Design, 
prototype,  debug,  &  test  embed¬ 
ded  hardware,  radio  sys.,  & 
software;  perform  simulation, 
schematic  entry  &  PCB  layouts. 
M.S.  in  Elec.  Eng.,  Comp  Eng., 
or  rel.  field  &  5  yrs.  rel.  exp.  or 
equiv.  educ.  &  exp.  5  yrs.  exp.  to 
include:  A/D  &  D/A  conversion; 
DSP  sys.  hardware;  Assembly; 
C/C++;  in-circuit  emulators  & 
logic  analyzers;  PCB  layout 
tools.  Send  apps.  to  Marv  Van 
Wyk,  Vermeer  Mfg.  Co.,  1210 
Vermeer  Rd  East,  Pella,  Iowa 
50219. 


Manager  of  Information  Services 
&  Operations.  Manage  network 
and  computer  infrastructure, 
web  site,  and  user  support;  create 
and  implement  operational 
procedures.  Prepare  contingency 
plan  for  e-mail  server,  financial 
applications  server,  RDBMS 
server,  and  Internet.  Evaluate 
and  implement  Internet  and  LAN 
security.  Manage  network 
cabling  infrastructure  based  on 
AT&T  standards;  monitor  LAN 
and  WAN  performance.  Manage 
and  troubleshoot  high-speed 
modems  and  switches  tor  leased 
line,  T1  lines,  etc.  Install,  trou¬ 
bleshoot,  and  monitor  software 
and  hardware  based  routers 
connecting  overseas.  Design 
network  connection  between 
European,  U.S.  and  Asian  offices, 
install,  manage,  and  troubleshoot 
remote  connectivity  for  European, 
South  American,  and  Asian 
Offices.  Plan  for  new  Sun-based 
servers  to  run  RDBMS  system; 
install  connectivity  from  local  to 
remote  client.  Must  have  Bache¬ 
lor's  degree  in  Computer  Science 
or  related,  plus  four  years  expe¬ 
rience.  Must  be  able  to  design 
networks  over  T1  and  leased 
lines,  provide  network  manage¬ 
ment.  security,  and  troubleshoot¬ 
ing;  use  IP  routing  technologies, 
gigabit  ethernet,  remote  access 
with  VPN  connectivity,  Check- 
Point  Firewall-1,  Cisco  Catalyst 
Switches,  VLAN,  and  Sun  Solaris. 
Must  have  knowledge  of  Asian 
and  European  telecommunica¬ 
tions  standards.  Send  resume 
with  cover  letter  to  Genetic  ID, 
Attn:  Jane  Pappin,  501  Dimick 
Drive,  Fairfield,  Iowa  52557. 


Oracle  Computer  Applications 
Developer  (various  assignments 
as  position  evolves),  under 
supervision  of  supervisory 
personnel,  to  design,  develop, 
test,  implement  and  debug 
computer  software  applications  in 
Oracle  specific  technology 
including  writing  SOL  and  PL/SQL 
statements  manually,  and  grow 
with  Oracle  technology  as  it 
evolves  to  develop  cutting  edge 
Oracle  skill  set  commensurate 
with  the  technology  as  it  evolves 
utilizing  the  ability  to  write  SQL 
and  PL/SQL  statements  manual¬ 
ly  and  the  ability  to  grow  with  Or¬ 
acle  technology  as  it  evolves  (as 
evidenced  by  present  proficiency 
in  Oracle  7.X,  8.0  and  8.i).  Re¬ 
quires  Bachelors  or  equivalent 
level  degree  in  Computer  Sci¬ 
ence,  Math,  Physics  or  Engineer¬ 
ing  or  a  closely  related  field.  Qual¬ 
ified  applicants  must  presently  be 
eligible  for  permanent  employ¬ 
ment  in  the  United  States.  Suc¬ 
cessful  applicant  must  be  able  to 
perform  job  duties  on  date  of  ap¬ 
plication  and  be  able  to  pass 
Wonderlic  math  and  logic  and 
Achiever  business  skills  tests. 
Send  resumes  to  Mr.  Jeff  Knott, 
Employment  Manager,  TALX  Cor¬ 
poration,  1 850  Borman  Court,  St. 
Louis,  Missouri  63146.  An  equal 
opportunity  employer. 


TECMAG  is  a  scientific  research 
and  technology  based  organiza¬ 
tion  specializing  in  manufacturing 
of  Nuclear  Magnetic  Resonance 
(NMR),  Nuclear  Quadrupolar 
Resonance  (NQR),  and  Magnetic 
Resonance  Imaging  (MRI) 
equipment  and  software  including, 
computer  systems,  scientific  and 
engineering  software,  and  data 
acquisition  systems.  We  are 
currently  looking  for  the  following: 

Software  Engineers:  Research, 
design,  develop,  and  maintain 
software  for  scientific  and  tech¬ 
nological  applications  including 
use  in  NMR,  NQR,  and  MRI 
applications.  Develop  and  direct 
system  procedures,  programming 
and  design  using  knowledge 
of  data  processing,  hardware 
interface,  display  graphics,  and 
Windows  NT/2000  GUI  applica¬ 
tions.  Utilize  strong  C++,  MFC, 
and  numerical  analysis  skills, 
including  advanced  scientific 
mathematical  algorithms,  and 
automation  skills.  Requires  a 
Master’s  degree  in  Computer 
Science  and  1  +  years  of  experi¬ 
ence  in  position  offered. 

Send  Resume  to:  Gloria  at  6006 
Beilaire  Blvd.,  Suite  #117, 
Houston,  Texas  77081  or  send 
via  e-mail:  jobs@tecmag.com 


Computer/Info  Systems 

SENIOR  PROGRAMMER/ 
ANALYST 

We  are  a  privately  owned 
$50  billion,  AAA-Aaa  rated 
financial  institution  providing 
central  banking  services  for 
thrifts,  banks,  and  credit  unions. 
We  currently  have  an  excellent 
opportunity  available  for  a  Senior 
Programmer  Analyst.  Responsi¬ 
bilities  include  analyzing,  design¬ 
ing,  coding  &  implementing  soft¬ 
ware  systems,  programs  & 
applications  using  Microsoft 
Access,  Visual  Basic,  SQL  Server 
&  Microsoft  Windows  NT ;  prepare 
detailed  project  plans  &  specifi¬ 
cations;  provide  technical  support; 
create  &  maintain  system  docu¬ 
mentation;  prepare  status  reports 
for  management;  act  as  project 
leader  on  specific  projects. 

We  require  a  Master's  degree 
in  Computer  Science  or  Infor¬ 
mation  Systems  required;  1  year 
experience  in  the  position  or 
1  year  as  Data  Analyst  and/or 
Programmer  Analyst  required. 
Related  occupation  must  include 
experience  in  analyzing,  design¬ 
ing,  coding  &  implementing  soft¬ 
ware  systems,  programs  and 
applications  using  Microsoft 
Access,  Visual  Basic  and  SQL 
Server.  Excellent  oral/written 
communication  skills. 

We  offer  a  competitive  salary 
and  comprehensive  benefit 
package  including  a  401  (k)  plan. 
Qualified  candidates  should 
send  resumes  with  cover  letters, 
including  salary  requirements  to: 
Human  Resources  Department, 
Federal  Home  Loan  Bank  of 
Chicago,  111  East  Wacker  Drive, 
Suite  800,  Chicago,  IL  60601, 
e-mail  hr@fhlbc.com  ,  or  fax  to 
(312)565-5812.  EOE  M/F/D/V. 


ECAL  Solutions  Inc.,  provides 
information  technology  consul¬ 
tation  services  with  highly  quali¬ 
fied  and  committed  professionals 
for  the  clients  to  optimize  and 
maximize  their  output.  We  are 
looking  for  the  following  posi¬ 
tions: 

Software  Engineers:  Research 
and  analyze  web  and  software 
applications.  Develop  and  ad¬ 
minister  the  e-commerce  appli¬ 
cations  in  Oracle,  DB2,  SQL 
Server,  and  Sybase  using 
Java.WebLogic,  JRun,  Jbuilder, 
XMLSpy,  Excelon  Stylus  and 
related  technologies  on  Windows 
and  UNIX.  Requires  a  Master's 
in  Computer  Science  or  Engi¬ 
neering  or  related  field  and  1 
year  of  experience. 

Programmer  Analysts:  Design 
and  develop  client-server  appli¬ 
cations  using  Oracle  Financials. 
Customize  payable  order,  con¬ 
versions,  interfaces,  manage  new 
products  or  enhance  existing 
products  using,  VB,  SQL  Server, 
PERL,  ASP,  and  XML.  Analyze 
business  procedures,  solve 
problems,  redefine  and  convert 
data  to  a  programmable  form. 
Requires  a  Bachelor’s  in  Com¬ 
puter  Science  or  Engineering  or 
a  related  field  and  2  years  of 
experience. 

Send  Resume  to:  HR,  ECAL 
Solutions  Inc.,  9207  Country 
creek  Drive,  Suite  #  207,  Houston, 
Texas  77036  or  via  e-mail  at: 
hr@ecalsolutions.com 


Systems  Engineer 

Test,  install  and  maintain  computer 
operating  systems;  monitor  and 
install  data  communication  lines; 
maintain  the  NT  infrastructure; 
develop,  implement  computer 
networking  plan;  test  and  imple¬ 
ment  Chinese  interface  of  the 
chips  of  elevators.  Master 
degree  in  computer  science  is 
required.  Send  resume  to  Mr. 
Marvin  W.  Schumacher,  Schu¬ 
macher  Elevator  Company,  Inc., 
One  Schumacher  Way,  Denver, 
IA  50622. 
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SIEMENS 

Take  a  Closer  Look. 

It's  a  great  feeling  to  work  for  a  company  and 
know  you  really  belong  there.  When  the  envi¬ 
ronment,  the  people,  and  the  opportunity 
exceed  your  expectations  and  your  hard  work 
is  appreciated. 

Software  Engineer 

We  are  seeking  a  Software  Engineer  to  design, 
code,  implement,  and  test  complex  product 
enhancements.  Other  responsibilities  include 
researching  and  coordinating  new  features  con¬ 
cepts;  analyzing  problems  and  suggesting  inno¬ 
vative  solutions;  designing  and  testing  plans; 
training  and  reviewing  design  work  of  program¬ 
mers.  Requires  a  Master’s  or  equivalent  in 
CompSci,  Information  Systems,  Engineering,  or 
related  field.  In  lieu  of  a  Master’s  Degree,  a 
Bachelor's  Degree  plus  5  years  as  a  Programmer 
is  required.  Must  have  proficiency  in  JAVA,  JAVA 
Servlets,  JAVA  Server  Pages,  SQL,  XML,  Web 
Server,  JAVA  Script,  HTML,  and  DHTML. 

Siemens  Health  Services  specializes  in  develop¬ 
ing  clinical,  financial,  and  management  solu¬ 
tions  that  support  leading  health  providers 
across  the  continuum  of  care.  As  an  integral  part 
of  our  organization,  you'll  enjoy  highly  competi¬ 
tive  compensation,  including  a  wide  array  of 
benefits,  and  professional  development  oppor¬ 
tunities. 

Isn’t  it  time  you  took  a  closer  look? 

FAX:  (610)219-8266 
Email:  human.resources@smed.com 
Source  Code:  RADMCPW00G 
www.smed.com/careers 

Equal  Opportunity,  Affirmative  Action  Employer. 


Sr.  Web  Developer  -  At  Quest 
Diagnostics  Inc,  we've  become 
the  nation's  most  respected 
name  in  diagnostic  testing  by 
focusing  on  integrity,  innovation 
and  quality.  We've  created  an 
environment  where  dedicated 
professionals  can  learn,  grow 
and  advance  -  ail  in  an  atmos¬ 
phere  of  pride.  We're  currently 
seeking  a  Sr.  Web  Developer 
to  be  based  in  Lyndhurst,  NJ. 
Candidate  will  design  database 
models,  business  and  presenta¬ 
tion  logic,  research  and  develop 
complex  web  applications.  Re¬ 
quirements:  Bachelor’s  degree  in 
Computer  Science,  Electronics, 
or  related  field.  3  years  experi¬ 
ence  in  OOAD/OOP,  RDBMS, 
transactional  middleware  or  web 
application  servers.  Knowledge 
of  3-tier  architecture  and  devel¬ 
opment  of  complex  web  applica¬ 
tions  and  corporate  web  sites 
also  required.  EOE/M/F/D/V. 
Please  add  source  code:  SWD- 
JG  and  forward  your  resume  to: 
Email:  questdiag@alexus.com; 
Fax:  877-588-9942  or  mail  to: 
Quest  Diagnostics  Incorporated, 
P.O.  Box  3597,  Scranton,  PA 
18505. 


Full-time  Project  Manager  of 
Accounts.  Document  &  manage 
project  plans,  scope,  objectives 
&  timeline  of  various  projects  for 
assigned  accounts.  Supervise  & 
direct  project  team  members. 
Responsible  for  direct  communi¬ 
cations  w/  clients,  monitor  analysis 
&  evaluations  regarding  clients 
business  &  technical  requirements 
to  insure  quality  of  the  imple¬ 
mentation  &  customer  satisfaction . 
Work  w/  Visual  Basic,  C,  C++, 
SQL  Server,  MS  Access,  Oracle, 
Sybase  &  Cold  Fusion.  Must 
have  a  Bachelor's  degree  in  CS, 
Computer  Engineering  or  related 
field  Must  have  2  yrs  exp  in  job 
offered  or  position  w /  same 
duties.  Salary:  $60,000.  Send 
resume  to  Betsy  Moya,  Serna, 
701  Waterford  Way,  Suite  300, 
Miami  Florida  33126. 


IT  SUPPORT  ENGINEER: 
Designs,  develops  and  main¬ 
tains  software  for  LINX  data 
collection  terminals.  Assembles 
and  maintains  PC  hardware 
including  POS  and  TPOS  sys¬ 
tems  (pole  displays,  receipt 
printers,  scanners  and  network). 
Installs  and  supports  ICVERIFY 
multi-user  credit  authorization 
service.  Designs,  develops  and 
maintains  hardware,  software 
for  RF  data  collection  systems. 
Designs,  develops  and  main¬ 
tains  applications  used  in  retail 
stores  and  back-office  systems 
utilizing  Visual  Basic  6.0,  Crystal 
Reports  8.0  and  relational 
databases.  Provides  bilingual 
(Spanish-Engiish)  "Help  Desk” 
support  for  stores  and  support 
center  users,  including  off-hours 
on-call  support.  Job  is  in  Boca 
Raton,  FL.  40  hrs.  weekly,  9-5PM, 
$88,000.00/yr.  Bachelor's  degree 
or  equivalent  in  Systems  Engi¬ 
neering  or  related  field  and  2 
years  experience  in  job  offered. 
Fax  resume  to  99c  Stuff,  LLC., 
Attention  Russ  Field  (561)  999- 
0515 


SOFTWARE  ENGINEER 

The  Software  Engineer  shall 
perform  systems  architecture, 
systems  analysis  and  design. 
Internet  technologies,  program¬ 
ming,  programming  languages, 
database  designs,  data  modeling, 
database  programming,  Java 
and  C++.  Must  have  a  minimum 
of  a  Masters  Degree  in  Engineer¬ 
ing  Science,  Computers  or  related 
expenence;  will  accept  Bachelor's 
Degree  plus  five  years  experience 
as  described  above. 

Salary  $68,000.00  per  year, 
full  time,  plus  standard  benefit 
package. 

Send  two  copies  of  letter  of 
application  and  resume  to: 

Job  Order  #2001 -828 
Post  Office  Box  989 
Concord,  NH  03302-0989 


INFORMATION 
TECHNOLOGY 
.  .  .  .  OPPORTUNITIES 

The  Gillette  Company  is  the 
wortd  leader  in  more  than 
a  dozen  consumer  product 
categories.  Global  World  Class 
operations  are  increasingly 
dependent  on  Information  Tech¬ 
nology.  Exciting  opportunities 
exist  in  global  business  process 
integration  initiatives.  We  are 
currently  seeking  the  following 
highly  qualified  professionals  to 
join  the  Gillette  IT  team  in  the 
Boston  area. 

The  following  positions 
commonly  require  a  Bachelor's 
degree  (or  equivalent)  in 
Computer  Science,  MIS, 
Business  Admin.,  or  similarly 
relevant  field,  and  3-5  years 
relevant  experience. 

I  Staff  Programmer  Analysts 

!  (SAP)  Staff  Basis  Adminis- 
trators/Con-figuration- 
Integration  Specialists/ 
Application  Developers 

I  Data  Warehouse  Architects/ 
Developers/Database 
Administrators 

I  Telecommunications 
Analysts 

Starting  salaries  range  from 
$56,100  to  $119,000  per  year, 
together  with  paid  vacation, 
medical,  dental,  life  and 
disability  insurances,  and  other 
industry-competitive  benefits. 

Please  mail  /  email  resume  to: 
The  Gillette  Company,  Prudential 
Tower  Building,  Boston  MA 
02199-8004  ATTN:  Elizabeth 
McFarlen,  Senior  Human 
Resources  Representative 
Email:  www.Gillette.Corn. 

The  Gillette  Company  is  an 
equal  employment  opportunity 
employer 


Sr.  Software  Eng'rs:  Dsgn,  dvlop 
&  implement  web-based  sw 
applica’n  w/ASP,  SQLServer 
2000,  7.0&6.5,  ADO,  JavaScript, 
VBScript,  DHTML,  HTML;  Dsgn 
DB  &  frontend  for  applic’n  w/ 
SQL,  Oracle8.x,  &  convert  DB 
from  DB2/Oracle  into  SQLServer- 
based.  40h/w,  8-5,  BS  in 
computer-related  field/foreign 
equivalent,  &  5  yr  wk  exp.  in  job 
offered  or  in  any  other  position 
involv’g  ASP,  DB2/Oracle,  & 
SQLServer.  Resume  to  L.  Ward, 
Best  Software,  Inc.  888  Exec.  Ctr 
Dr.  W,  #300,  St.  Pete,  FL33702, 
or  at  laurie.ward@bestsoftware. 
com  fax:  727-578-2178 


Full-Time  IMC  Senior  Database 
Consultant.  Responsible  for 
interacting  with  client  managers, 
integrators  and  users  regarding 
functional  aspects  of  assigned 
projects.  Identify  client's  business 
requirements,  determine  en¬ 
hancements,  create  functional 
design  specifications,  and  provide 
change  management  guidance 
working  with  BSCS,  Gupta/ 
Centura,  Oracle,  Unix,  C,  PL/ 
SQL,  Visual  C++,  Visual  Basic, 
Visual  Fox  Pro,  MS  SQL,  Access 
and  TCP/IP.  Assist  clients  with 
conversion  strategies  and  plans 
and  resolve/troubleshoot  all  con¬ 
version  issues.  Develop  testing 
strategies,  plans  and  analyze 
codes  to  determine  database 
population  and  defects.  Must 
have  Bachelor's  degree  in  Com¬ 
puter  Science,  any  Engineering 
discipline  or  related  field.  Foreign 
degree  equivalent  accepted. 
Must  have  4  yrs.  exp.  in  job 
offered  or  position  w /  same  duties. 
Salary:  $66,000  Send  resume  to 
Betsy  Moya,  Serna,  701  Waterford 
Way,  Suite  300.  Miami,  Florida 
33126. 


Network  Manager 
(New  York,  NY) 

Royalbiue  financial  corporation, 
a  leading  supplier  of  global  trading 
software  with  offices  in  New  York, 
London,  Frankfurt  and  Tokyo,  re¬ 
quires  a  fidessaNet  Network 
Manager.  Royalbiue  has  devel¬ 
oped  the  fidessa  trading  platform 
to  provide  the  most  complete 
range  of  applications  available 
for  trading  cash  equities  across 
the  world's  markets.  Responsi¬ 
bilities  include: 

•  Network  design,  installation  and 
support; 

•  Managing  mid-to-large  (500+ 
node)  network; 

•  Cisco  router/switch  configuration; 

•  Network  management  applica¬ 
tions 

Applicants  will  have  a  Bachelor 
of  Science  degree  in  Telecom¬ 
munications,  Engineering  or 
a  closely  related  field  and  expe¬ 
rience  with  engineering  and 
integrating  connectivity  to  Equities 
Trading  Exchanges  (eg  NYSE, 
NASDAQ)  &  ECN's  (eg  Island. 
Archipelago). 

Certifications  Required; 

•  CCNP  (Cisco  Certified  Network 
Professional); 

•  CCIE  (Cisco  Certified  Internet¬ 
working  Expert),  or  actively 
pursuing; 

•  MCSE  (Microsoft  Certified 
Systems  Engineer) 

•  SUN  Solaris  certified,  or 
actively  pursuing. 

Apply  to  Royalbiue  Financial 
Corporation,  17  State  Street, 
New  York,  NY  10004,  Attn:  Human 
Resources  (NM). 


Consulting  comp,  in  NJ  req.  for 
its  ongoing  conversion  Projects 
a  System  Analyst  w/BS  Deg.  or 
its  equivl.  &  2  yrs.  exp.  of  design 
exp.  in  Financial/Accounting 
packages.  Candidate  should 
have  req.  skills  on  the  AS/400/ 
OS/400/SYNON  4E/JD  Edwards 
&  Oracle  Platform. 

Emolmts.,  is  based  on  edu.  & 
exp.  Travel  &  relocation  req.  to 
unanticipated  client  sites.  Send 
resumes  to:  Attn  RECRUITER, 
TRANSWORLD  INFO.  SYS¬ 
TEMS,  Inc.,  33  WOOD  AVE.,  7 
FL.  ISELIN,  NJ  08830 


Software  Engineer  (Melrose  Park, 
PA)  Analyze,  design,  develop, 
implement  programs  for  com¬ 
mercial  &  financial  applications. 
Uses  VB  6. 0/5.0,  Oracle  3i/8.0, 
SQL+,  PL/SQL,  web  technologies 
COM,  DCOM,  MTS,  ActiveX,  VB 
Script  DHTML.  BS  Comp.  Sci./ 
Eng.  Fax  resume  215-782-2083 
Ref.  RM. 


Systems  Analyst  needed  for 
Miami  computer  sales  and 
export  co,  to  review  computer 
system  capabilities,  workflow, 
and  scheduling  limitations.  Min 
req.  4  yrs  exp.  Send  resumes  to 
TWC  The  Wise  Computer,  Inc. 
P.O.  Box  226438  Miami,  FL 
33122. 


InfiniSwitch  is  a  leader  in  Infini¬ 
Band  switching  technology  for 
data  centers.  We  are  currently 
seeking  Software  Quality  Assur¬ 
ance  Engineers.  Our  Software 
Quality  Assurance  Engineers 
will  work  with  the  InfiniBand 
specifications  and  with  input 
from  other  engineering  team 
members  to  isolate  and  expose 
system  and  sub-system  problems 
and  develop  resolutions.  They 
will  also  develop  and  execute 
test  plans  and  cases  required  to 
fully  test  and  qualify  Infiniband 
Switch  products,  and  conduct 
software  integration  testing, 
load/performance  testing  and 
install  Operating  Systems  and 
Networks.  Requirements  include 
a  MS  in  CS  or  closely  related 
and  two  years  experience  as 
Software  Quality  Assurance 
Engineer  (or  will  accept  BS  in 
CS  and  five  years  experience, 
two  of  which  are  in  QA).  Also 
required  is  high  degree  of  profi¬ 
ciency  working  with  following: 
Linux  or  Windows  2000  operating 
systems;  Network  switches,  fibre- 
channel  SAN  components,  or 
SNMP  Management  testing;  and 
application  load/artificial  traffic 
load  generation,  test  automation, 
or  performance  testing.  Interested 
applicants  may  send  their 
resume  to  Human  Resources, 
InfiniSwitch  Corporation,  134 
Flanders  Road,  Westborough, 
MA  01581.  F  508-870-3146. 


Several  computer  related 
positions  available  for  a  large 
communications,  marketing 
and  distributing  company. 
Degree,  technical  skills  & 
experience  vary  per  position. 
Send  resume  to  Ernie  Mueller, 
CMD  Services,  Inc.,  3060 
Premiere  Parkway,  Duluth, 
GA  30097. 


PRODUCT  MANAGER  (INTER¬ 
NET),  U.K.  &  EUROPE  ISSUES 
-(New  York,  NY),  define  Product 
Vision  &  Direction  For  All 
Company  Products  (Internet  & 
Connectivity  Solutions)  in  UK 
and  Europe:  Act  as  primary  point 
of  contact  for  UK  sales  and 
marketing  teams;  Oversee 
market  analysis  and  oversee  all 
product  development  initiatives 
for  region;  act  as  an  interface 
between  US  product  manage¬ 
ment  and  UK/Europe.  Bachelors 
Degree  in  Business  Administra¬ 
tion/Economics,  1  year  experi¬ 
ence.  40  hours  per  week,  9:00  AM 
to  5:00  PM.  Send  resumes/letter 
to:  HR  Dept.,  Globix  Corporation, 
1 39  Centre  Street,  New  York,  NY 
10013. 


Exp'ed  Prog/Sys  Analysts,  Net¬ 
work  Engineers,  DBAs  and  S/W 
Engineers  required  for  branch 
locations  in  Santa  Clara,  CA,  Mt. 
Laurel  NJ,  Conshohocken,  PA. 
Skill  sets  -  C,  C++,  Java,  HTML  on 
UNIX/Windows;  Visual  Basic, 
Visual  C++,  Power  Builder;  Oracle, 
PL/SQL,  Pro’C;  UNIX,  Windows 
2000/NT  Sys.  Admin.  Require  BS/ 
MS  in  CS/Engg/Math/Business/ 
Science  (or  its  foreign  equiv  and/ 
or  equiv.  in  education  and  exp.) 
And  relevant  exp.  Travel/Relocation 
required.  Salary  commensurate 
with  exp.  Resumes  to:  HR,  Fourth 
Technologies,  27  Roland  Avenue, 
STE  B,  Mount  Lourel,  NJ  08054. 
Indicate  on  resume  the  branch 
office  you  are  applying  for. 


**  Kama  Consulting  Inc. 

TOP  SS  s,  W2  or  1099 

We  are  a  fast  growing 
Consulting  company  based 
in  New  Jersey 
Excellent  opportunities  for 
Programmers, 

Systems  Analysts,  DBAs 

Sun  Solaris  System  Admins. 

Natural.  Powerbuilder. 
ADABAS,  ORACLE,  SYBASE. 

PROGRESS.  COBOL 
TCP/IP,  Delphi/VB,  Windows  NT 

Send  your  resume  to 
Rod  McFadden 
Kama  Consulting 

Fax:201-934-7166 
EmaibKamaco®  aol.com 


Programmer/Analyst  (4  openings): 
Design,  test,  code,  implement 
and  maintain  for  internal  and 
external  web-based  3-tier  appli¬ 
cation  architecture  projects  using 
HTML,  J2SE,  Java  SERVLETS, 
XML,  EJB,  Apache-JServ,  Java¬ 
script.  Req.  B.Sc.  or  its  foreign 
degree  equivalent  in  C.  Sci.,  EE, 
or  other  related  field  w /  at  least  2 
yrs.  exp.  in  job  offered.  Resume 
to:  HR  Manager  (job  code 
CW0102),  Ptek  Holdings,  3399 
Peachtree  Rd.  N.E.  Ste  600, 
Atlanta,  GA  30326 


Software  Engineer  (Melrose  Park, 
PA)  Programming  in  NET,  VB/ 
ASP+,  MTS,  Tuxedo,  CDO, 
T-SQL.  Maintains  SQL,  Exchange, 
IIS  Servers.  Designs  &  Develops 
applications  like  HRMS,  Airline 
Ticketing,  EBiz  Medical  Soft¬ 
ware.  Prepares  Technical  Project 
Proposals.  Fax  resume  215-782- 
2083  Ref.  DD. 


Senior  Database  Administrators: 
Newton,  MA  office  needs  expe¬ 
rienced  individuals  for  perfor¬ 
mance  monitoring,  tuning  and 
testing.  Send  resumes  to:  C. 
Wyzga,  EIS-CW02-SDBA,  Eagle 
Investment  Systems,  65  LaSalle 
Rd.,  W.  Hartford,  CT  06107. 
EOE/F/M/V/D/Legal  workers 
only  please. 


PROGRAMMER/ANALYST  to 
analyze,  design,  develop,  test, 
integrate  and  implement  appli¬ 
cation  software  using  object 
oriented  Techniques,  Java, 
Websphere,  J  Builder,  JSP,  XML, 
XSLT,  XPATH,  XLINK,  DB2, 
Oracle.  Ant,  Resin  and  Tapestry. 
Require:  BS  Degree  &  5  years 
of  Experience  or  Masters  in 
Computer  Science/related  sub¬ 
jects  &  2  years  of  Experience. 
Salary:  $50-60K  Fax  resumes  to 
770-973-0706  or  email  To  ameen 
©software  superheroes.com 
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- : -  n  cities  nationwide  covering  the  latest 

seminars  Si  6V6ntS  networking  technologies.  All  of  our  sem 
mars  are  also  available  for  customized 
on-site  training.  For  complete  and  imme¬ 
diate  information  on  our  current  seminar  offerings,  call  a 
seminar  representative  at  800-643-4668,  or  go  to  www.nwfu- 
sion.com/seminars. 


Publicize  your  press  coverage  in  Network 
World  by  ordering  reprints  ot  your  editorial 
mentions.  Reprints  make  great  marketing 
materials  and  are  available  in  quantities  of 
500  and  up.  To  order,  contact  Reprint 
Management  Services  at  (717)  399-1900  x124 
or  E-mail:  rtry@rmsreprints.com 


These  indexes  are  provided  as  a  reader  service.  Although  every 
effort  has  been  made  to  make  them  as  complete  as  possible,  the  pub¬ 
lisher  does  not  assume  liability  for  errors  or  omissions. 
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VoIP 

continued  from  page  1 

Internet  access  and  private  IP 
frame  relay  customers  this  year. 

When  WorldCom  launched  the 
service  last  year,  the  carrier  said  it 
was  using  SIP  for  call  set-up  and 
termination,  but  was  not  ready  to 
roll  out  SIP  support  to  the  desk¬ 
top. 

The  University  of  Pennsylvania 
tested  IP  Communications  and 
the  SIP  phones  as  part  of  an  ongo¬ 
ing  study  of  integrating  existing 
telephony  equipment  into  a 
voice-over-IP  environment. 

“We  did  test  the  Cisco  7960  and 
Pingtel  xPressa  phones.  Both  were 
well  received  by  users,  and  there 
were  no  noticeable  ergonomic 
differences  or  differences  in  call 
quality  with  either  product,”  says 
Steve  Blair,  senior  network  engi¬ 
neer  at  the  university. 

Blair  says  he  was  “most 
impressed  with  the  quality  of  the 
technical  support”  when  he  was 
testing  IP  Communications.  While 
the  beta  test  ended  late  last  year, 
Blair  still  is  weighing  his  voice- 
over-IP  options. 

“The  key  benefit  of  SIP  is  its 
interoperability  with  the  [public 
switched  telephone  network 
(PSTN)], "says  Lisa  Pierce, an  ana- 


WorldCom  talking  VoIP 

Plans  for  WorldCom’s  IP  Communications  voice-over-IP 
service  include: 


Enhancements  that  will  • 

let  customers  integrate 
voice  directly  onto  a  LAN. 

Support  in  March  for  • 

native  Session  Initiation 
Protocol. 


Q2  target  to  make  IP  Communi¬ 
cations  available  to  all  dedica¬ 
ted  Internet-access  customers. 

Q3  goal  to  integrate  voice-over- 
IP  offering  into  dedicated  IP 
VPN  and  private  IP  services. 


lyst  at  Giga  Information  Group. 
The  signaling  protocol  efficiently 
hands  off  traffic  between  an  IP 
network  and  the  traditional  tele¬ 
phone  network,  especially  com¬ 
pared  to  other  voice-over-IP  proto¬ 
cols  such  as  H.323.  It’s  a  positive 
development  that  WorldCom  is 
moving  ahead  with  native  SIP 
support  as  more  companies, such 
as  AOL  Time  Warner  and 
Microsoft,  get  behind  the  proto¬ 
col,  she  says. 

Although  WorldCom  is  not  the 
first  service  provider  to  offer  users 
voice-over-IP  support,  it  is 
believed  to  be  the  first  in  the  U.S. 
to  offer  managed  SIP-enabled 
voice-over-IP  services  to  the  desk¬ 
top.  AT&T  also  offers  voice-over-IP 
support  for  its  managed  Internet 
access  and  frame  relay  cus¬ 


tomers,  but  AT&T  uses  H.323  sig¬ 
naling  technology 

“Native  SIP  support  will  allow 
new  sites  to  set  up  a  traditional 
phone  system,  from  a  feature  per¬ 
spective,  without  investing  in  a 
PBX,”says  Barry  Zipp, senior  direc¬ 
tor  of  enhanced  voice  services  at 
WorldCom.  “This  will  lower  the 
cost  of  new  site  implementation 
dramatically  New  site  setup  [with 
native  SIP  support]  is  half  what  it 
would  be  with  a  PBX  system.” 

Users  can  expect  this  type  of 
savings  when  setting  up  an  office 
with  about  250  or  more  employ¬ 
ees,  Zipp  says. 

“To  support  native  SIP  you  have 
to  replicate  and  enhance  the 
functions  that  are  resident  in  a 
PBX  or  Centrex  environment,” 
which  is  what  WorldCom  is  doing, 


he  says.  Business  users  can  expect 
features  such  as  call  forwarding, 
call  transfer  and  four-digit  dialing. 

WorldCom  also  plans  to  launch 
a  number  of  SIP  voice  applica¬ 
tions,  including  voice  mail.  The 
carrier  is  deploying  SIP  voice  mail 
servers  from  Webley  on  its  vBNS+ 
network,  where  all  IP  Communi¬ 
cations  call  signaling  and  hand- 
offs  to  the  PSTN  takes  place. 

Although  WorldCom  initially 
planned  to  move  IP  Communi¬ 
cations  support  over  to  its  com¬ 
mercial  Internet  backbone,  Zipp 
says  the  carrier  will  continue  sup¬ 
porting  the  service  on  the  vBNS-f 
network  for  the  near  term.  This 
network  was  developed  for  the 
academic  community  and  sup¬ 
ports  advanced  technologies 
such  as  IPv6. 

“The  vBNS+  network  has  inter¬ 
connections  into  all  our  data  net¬ 
works.  It  might  not  be  the  most 
efficient  setup,  but  right  now  it  lets 
us  get  to  the  other  networks  and 
we’re  not  seeing  any  delays,”  Zipp 
says.  The  question  of  efficiency 
comes  into  play  when  WorldCom 
rolls  out  IP  Communications  ser¬ 
vices  to  its  Internet  access  and  IP 
VPN  customers. 

WorldCom  expects  to  an¬ 
nounce  in  the  second  quarter  IP 
Communications  support  for  its 


managed  dedicated  Internet 
access  customers.  If  IP  Com¬ 
munications  signaling  and  ap¬ 
plication  support  were  deployed 
on  WorldCom’s  legacy  UUNET 
backbone,  an  Internet-access  cus¬ 
tomer’s  traffic  would  not  have  to 
traverse  a  second  network,  the 
vBNSr  network,  before  it  reaches 
the  PSTN. 

In  the  third  quarter  WorldCom 
also  will  roll  out  IP  Commun¬ 
ications  support  to  its  dedicated 
IP  VPN  and  Private  IP  frame  relay 
customers.  This  support  will  let 
customers  integrate  voice  directly 
onto  a  VPN  by  using  an  existing 
PBX  or  by  going  for  a  complete 
overhaul  and  deploying  SIP- 
enabled  phones  on  each  user’s 
desktop. 

Zipp  says  WorldCom  is  develop¬ 
ing  an  IP  Communications  ser¬ 
vice  for  small  and  midsize  busi¬ 
nesses,  although  price  considera¬ 
tions  remain  an  obstacle  there. 

“The  SIP  phones  are  still  fairly 
expensive.  Some  vendors  are  get¬ 
ting  them  down  to  the  $100  range, 
but  the  phones  from  Cisco  and 
Pingtel  are  significantly  more 
expensive,”  Zipp  says. 

WorldCom  hopes  to  get  an  IP 
Communications  service  that  will 
run  over  DSL  ready  by  year-end, 
he  says.  ■ 


ComNet 
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Redline 

continued  from  page  15 

multiple  sessions  per  page. 

With  T/X  devices,  the  servers 
download  the  pages  to  the  T/X 
over  a  100M  bit/sec  Ethernet 
link  using  a  single  TCP  session. 
Once  it  has  the  page  image,  the 
T/X  shrinks  it  using  the  type  of 
compression  supported  by  the 
requesting  browser.  It  also 
weeds  out  data  that  the  brows¬ 
er  does  not  need  to  build  the 
page.  This  process  reduces  the 
volume  of  data  to  be  sent, 
requiring  less  Internet-access 
bandwidth. 

Over  time,  as  a  Web  site 
draws  more  hits,T/Xs  can  stave 
off  the  need  to  add  more 
server  hardware,  again  saving 
money  in  capital  outlay  and 
management. 

“The  more  machines  you 
have  to  administer  and  oper¬ 
ate,  the  more  your  costs  go  up,” 
Christy  says. 

The  T/X  2400,  which  costs 
$20,000,  supports  up  to  64  clus¬ 
ters  of  servers,  with  32  servers 
in  each  cluster.  A  smaller  ver¬ 
sion,  T/X  2100,  costs  $10,000 
and  serves  one  cluster  of  32 
servers  ■ 


said  the  company  should  soon 
have  access  to  even  more 
resources  given  that  Verizon, 
which  owns  9%  of  the  company,  is 
expected  to  increase  that  share  to 
80%  after  clearing  certain  regula¬ 
tory  hurdles. 

In  another  exchange,  World¬ 
Com’s  Crabtree  asked  how 
Equant  could  get  by  with  just  a 
155M  bit/sec  backbone, while  oth¬ 
ers,  including  her  company  boast 
a  10G  bit/sec  core.  Equant’s 
Maarleveld  seeks  only  the  largest 
international  customers,  whose 
individual  needs  are  high  but 
that,  in  sum,  don’t  represent  an 
enormous  bandwidth  drain. 
Equant  does  not  sell  to  other  car- 
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riers  or  hoards  of  consumers,  so 
its  backbone  needs  are  relatively 
modest,  Maarleveld  said.  “We  see 
no  reason  to  buy  a  lot  of  back¬ 
bone  we  don’t  need,”  he  added. 

Sprint  WorldCom  VPN  news 

Outside  of  the  debate,  Sprint 
and  WorldCom  announced  new 
VPN  services. 

Sprint  said  it  is  using  Cosine 
Communications  gear  to  deliver  a 
new  managed  network-based 
VPN  service,  slated  for  availability 
in  the  second  quarter. 

The  service  will  protect  cus¬ 
tomer  traffic  inside  IPSec  tunnels 
once  it  reaches  Sprint’s  network, 
although  traffic  will  run  unpro¬ 
tected  between  customer  sites 
and  Sprint  points  of  presence. 
Sprint  claims  the  service  will  be 
easier  for  it  to  manage  than  its 
existing  managed  VPN  service 
because  the  carrier  can  support 
many  customers  from  each  Co¬ 
sine  device.  While  Sprint  wouldn’t 
reveal  how  many  sites  it  can  sup¬ 
port  via  the  new  service  or  how 
much  it  will  cost,  it  said  the  offer¬ 
ing  should  appeal  most  to  com¬ 
panies  looking  to  build  out  large 
VPNs  that  would  be  too  difficult 
to  manage  and  too  time-con¬ 
suming  to  roll  out  themselves. 


Sprint’s  existing  managed  VPN 
service  relies  on  equipment 
placed  at  each  customer  site,  pro¬ 
tecting  the  access  links  between 
customers  and  Sprint  POPs,  but 
increasing  the  number  of 
machines  Sprint  must  manage  to 
deliver  the  service. 

Separately,  WorldCom  an¬ 
nounced  a  way  for  customers  of 
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its  IP  VPN  Dedicated  Access,  Fully 
Managed  service  to  measure  the 
latency,  usage  and  reliability  of 
their  VPN  connections.  These 
reports  are  available  in  daily, 
weekly  and  monthly  Web-based 
reports  via  a  new  service  called 
VPN  Interactive  Performance 
Reporting  (VIFeR).  There  is  no 
extra  charge  for  the  service.  ■ 
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Novell  Secure  Access 

Security  suite  includes  seven  products: 


Components 

Function 

BorderManager 

Content,  packet  filtering,  caching,  firewall, 
VPN,  Internet  access 

SecureLogin 

Single  sign-on  for  applications 

iChain 

External  authentication 

Modular  Authenti¬ 
cation  Service 

Biometric,  smart  card,  digital  certificates, 
tokens  and  authentication 

eDirectory 

Organize  and  store  individual  identity 
information  and  access  rights 

Account 

Management 

Synchronizes  NetWare,  Win  NT/2000, 
Solaris,  Linux  information  into  eDirectory 

NDS  Authentication 
Service 

Synchronizes  OS/390  Unix,  Linux,  AS/400 
user  information  into  eDirectory 

BorderManager 

continued  from  page  1 

veil  Directory  Services  Authen¬ 
tication  Services  (NDS-AS)  and 
Novell  Account  Manager  (NAM). 

SecureLogin  provides  single 
sign-on  capability  for  Windows, 
Web  and  host  applications; 
iChain  allows  authentication 
into  the  network  from  outside 
networks;  eDirectory  organizes 
and  stores  individual  identity 
information  and  access  rights; 
NMAS  enables  biometric,  smart 
card,  digital  certificates,  tokens 
and  proximity  card  authentica¬ 
tion;  and  NDS-AS  and  NAM  syn¬ 
chronize  user  information  from 
other  operating  systems  into 
eDirectory. 

Greg  Bernard,  a  financial  ana¬ 
lyst  for  Midwest  Capital  Markets 
in  Kansas  City,  Mo.,  says  the  focus 

is  right. 

“It  is  an  excellent  idea,”  Ber¬ 
nard  says. “Novell  is  on  the  right 
track,  especially  with  what  we’ve 
seen  with  viruses  and  other  net¬ 
work  intrusions  in  the  last  year.  If 
the  company  can  provide 
secure  networking  on  the 
Internet,  extranet  and  intranet, 
that’s  a  tremendous  market  for 
them  to  go  for.” 


Users  say  security  is  a  natural 
extension  to  Novell’s  NetWare, 
GroupWise,  ZENworks  and  Portal 
Services  products. 

“By  being  a  directory  service 
vendor,  Novell  by  default  is  a 
security  company”  says  Rocco 
Esposito, CTO  of  window-covering 
manufacturer  Hunter  Douglas  in 
Upper  Saddle  River,  N.J. 

Esposito  says  that  while  the 
security  focus  is  good,  Novell 
shouldn’t  try  to  fill  in  the 
gaps  by  developing  products, 
but  should  acquire  them 
from  vendors  such  as  Symantec 
or  McAfee. 

Novell’s  Secure  Access  bundle 
is  strong  in  single  sign-on, 
metadirectory  services  and  pass¬ 
word  management  capabilities, 
but  lacks  antivirus,  intrusion 
detection,  auditing  and  central¬ 
ized  administration  software, 
observers  say. 

“Intrusion  detection  is  fast 
becoming  an  absolute  must  for 
network  security,  and  soon  the 
BorderManager  firewall  product 
will  be  seen  as  lacking  if  it  does¬ 
n’t  include  an  [intrusion-detec¬ 
tion  system],” says  Ron  Diebert, 
network  and  systems  manager 
for  the  Baltimore  County  Gov¬ 
ernment  in  Towson,  Md. 


Competition  for  Novell’s  Secure 
Access  is  also  broad,  but  so  is 
the  market.  IDC  expects  sales 
of  authentication,  authorization 
and  administration  software  will 
grow  from  $2.8  billion  in  2000  to 
$9.4  billion  by  2005.  Single  sign- 
on  products,  of  which  Novell 
holds  a  30%  market  share,  will 
represent  a  significant  portion  of 
the  market,  IDC  predicts.  Com¬ 
puter  Associates’  eTrust  leads  the 
overall  security  software  market 


with  15.5%  of  sales,  followed  by 
IBM/Tivoli  Systems’  SecureWay 
with  11.2%. 

There  are  a  number  of  soft¬ 
ware  companies  with  special¬ 
ized  products  that  could  under¬ 
cut  Novell’s  security  push, 
including  Netegrity’s  Secure  Re¬ 
lationship  Management  single 
sign-on  product,  NetlQ’s  Admin¬ 
istration  Suite  and  CacheFlow’s 
Server  Accelerator  proxy  cache 
appliance. 


Meanwhile,  Novell  developers 
are  working  on  a  version  of  Bor¬ 
derManager  that  starts  to  bring  it 
up  to  snuff  with  other  products. 
They  will  add  Web-based  config¬ 
uration  of  packet  filters,  virus 
pattern  filtering,  a  client  for 
Windows  XP  and  Millennium 
Edition,  and  a  personal  firewall 
to  Version  3.7. 

Users,  who  realize  that  protect¬ 
ing  a  directory  and  its  user  iden¬ 
tity  and  access  rights  should  be 
the  primary  function  of  any  secu¬ 
rity  product,  say  these  changes 
are  long  overdue. 

Even  though  “BorderManager’s 
key  strength  compared  with 
other  firewall,  proxy,  VPN  soft¬ 
ware  has  always  been  its  direc¬ 
tory  integration,  the  current  ver¬ 
sion  was  starting  to  lag  behind 
other  vendors’  [product]  fea¬ 
tures,”  says  Michael  Ducharme, 
IT  manager  for  the  Anokiiwin 
Training  Center  in  Winnipeg, 
Canada.  “Also,  1  was  concerned 
that  BorderManager  3.6  configu¬ 
ration  and  management  would 
still  be  done  via  the  aging  [DOS- 
like]  console  interface,  while 
administration  for  all  other 
Novell  software  has  since 
moved  to  [the  Web] 

For  the  foreseeable  future, 
BorderManager  will  remain  Net¬ 
Ware-based,  although  future  ver¬ 
sions  will  remove  its  dependency 
on  NDS  eDirectory  and  work 
with  any  Lightweight  Directory 
Access  Protocol-compliant  direc¬ 
tory,  Novell  says.  The  company 
also  says  that  buyers  of  security 
suites  often  don’t  purchase  every 
component  and  therefore  may 
not  mind  that  BorderManager 
only  works  on  NetWare  servers.  A 
customer  may  choose  to  replace 
BorderManager  with  a  firewall 
from  Check  Point  Software  or  a 
single  sign-on  product  from 
Netegrity 

Some  users  even  say  it’s  not 
necessary  to  port  Border- 
Manager  to  other  operating  sys¬ 
tems’  platforms. 

“The  functionality  of  Border- 
Manager  is  appliancelike  and  in 
an  appliance  it  really  doesn’t 
matter  what  the  base  [operating 
system]  is,"  says  Chip  DiComo, 
manager  of  global  information 
systems  for  transportation  firm 
Heilman  Worldwide  Logistics  in 
Miami.  A  BorderManager  server 
could  easily  be  placed  in  a 
Windows  NT/2000  or  Unix  net¬ 
work  as  an  edge  device,  where 
it  would  provide  firewall,  VPN 
or  packet  filtering  services, 
DiComo  says.  8 
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NetlQ  keeps  up  with  Web  traffic  scalability 


■  BY  ANN  BEDNARZ 

ORLANDO  —  On  the  heels  of  naming  a 
new  leader,  NetlQ  is  set  to  offer  updated  Web 
analysis  software  that  crunches  Web  visitor 
data  five  times  faster  than  earlier  versions. 

CEO  Charles  Boesenberg  succeeds  com¬ 
pany  co-founder  Ching-Fa  Hwang,  who  is 
retiring  from  daily  operations  but  retains  the 
chairman’s  seat.  Boesenberg  took  over  just  in 
time  for  the  company’s  NetConnect  2002 
user  conference,  where  NetlQ’s  WebTrends 
division  is  unveiling  its  revamped  —  and 
renamed  —  high-end  Web  analytics  suite. 

Highlights  of  WebTrends  Intelligence 
Suite  (W1S),  formerly  known  as  Com- 
merceTrends,  are  its  improved  perfor¬ 
mance,  data  integration  tools  and  reporting 
options.  According  to  the  company, WIS  can 
process  and  analyze  Web  data  five  times 
faster  than  its  predecessor.  Behind  the  per¬ 
formance  gains  are  algorithm  adjustments 
that  let  the  software  more  efficiently  extract 
and  stitch  together  visitor  session  infor¬ 
mation  from  multigigabyte  log  files,  which 
record  events  sequentially  rather  than  per 
visitor. 

The  performance  increase  in  WIS  is  impor¬ 
tant,  says  Guy  Creese,  research  director  at 
Aberdeen  Group.  Along  with  competitors 
NetGenesis  and  Accrue  Software,  WebTrends 
faces  a  constant  battle  to  keep  up  with  enter¬ 
prise  scalability  demands  as  Web  traffic 
increases,  Creese  says.  At  an  active  site,  traffic 


can  grow  50%  every  six  months,  he  says. 

New  integration  tables  included  in  WIS  aim 
to  make  it  easier  to  share  data  with  other 
sources,  such  as  call  center  software,  to  cor¬ 
relate  Web-based  and  call  center  activities. 

A  new  custom  reporting  module  bundled  in 
WIS  is  based  on  Crystal  Decisions’  reporting 
technology.  The  WebTrends  Report  Designer 
supplements  350  predefined  reports  and  a 
high-end  reporting 
tool  called  Web¬ 
Trends  OLAP  Man¬ 
ager.  Where  Web¬ 
Trends  Report  De¬ 
signer  is  limited  to 
two  variables,  the 
online-analytical- 
processing-based 
reporting  engine 
lets  users  map  mul¬ 
tiple  variables  — 
such  as  the  number 
of  Web  site  hits  from 
users  in  New  England  who  responded  to  a 
particular  marketing  campaign  between  6 
p.m.and  midnight. 

For  even  more  sophisticated  data  analysis, 
NetlQ  is  partnering  with  Quadstone,  which 
makes  predictive  modeling  and  data  mining 
software.The  deal  is  aimed  at  businesses  that 
want  to  merge  customer  data  from  their  Web 
sites  and  offline  sources  for  a  view  of  histori¬ 
cal  data  and  future  buying  trends. 

WebTrends’  competitors  in  the  high-end 


analytics  market  have  made  similar  moves. 
Accrue  licenses  data-mining  technology 
from  NeoVista  (a  company  it  once  owned 
but  sold  last  year  to  JDA  Software). 
NetGenesis  partnered  with  —  and  since 
November  is  owned  by  —  data  mining  and 
predictive  analytics  company  SPSS. 

Where  the  three  competitors  differ  is  in  the 
breadth  of  their  Web  analytics  offerings, 
Creese  says.  Accrue  offers  a  midrange  prod¬ 
uct  in  addition  to  its  high-end  suite; 
NetGenesis  only  serves  the  high  end,  he  says. 
Only  WebTrends  has  a  full  soup-to-nuts  line¬ 
up,  Creese  says. 

WIS  is  available  now  starting  at  $30,000. 
Quadstone  for  WebTrends  pricing  is  not  yet 
available. 

Meanwhile,  the  company  also  will  an¬ 
nounce  its  NetlQ  SQL  Server  Management 
Suite,  which  is  the  company’s  first  foray  into 
database  management.  ConfigurationMana- 
ger  for  SQL  is  a  new  product  the  company 
says  helps  track  configuration  changes. 
NetlQ  also  will  begin  reselling  its  Recovery- 
Manager  for  SQL  Server  as  a  result  of  a 
reseller  agreement  with  Lumigent  Technolo¬ 
gies.  The  software  will  provide  real-time 
analysis  of  SQL  transaction  logs.  The  suite 
also  includes  NetlQ’s  AppManager  for  SQL 
Server.  The  products  are  slated  to  be  avail¬ 
able  in  March  or  April. 

Staff  Writer  Denise  Dubie  contributed  to  this 
story. 


New  NetlQ  CEO  Charles 
Boesenberg. 
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Opening  a  can 

“Just  another  thing  that  won ’t  work, 
to  add  to  software  that  doesn 't  work, 
hardware  that  doesn't  function,  and 
service  people  who  have  no  clue.  Just 
one  more  thing  to  separate  me  from 
the  machines  and  their  effective  use. 

Just  one  more  thing  to  be  made  obso¬ 
lete  by  the  ‘upgrade’ of  any  one  component.  The  very 
thought  of  the  return  of  dongles  makes  me  long  to  live 
in  a  Third  World  country.  At  the  moment,  stawation 
looks  preferable  although  I  would  doubtless  change 
my  mind  when  it  was  too  late!’ 

—  e-mail  from  Jane  Axtell 

7  am  not  generally  amused  by  people  who  tell  you 
why  you  should  be  happy  when  they  commit  crimes 
against  you.  Piracy  is  wrong.  But  software  manufactur¬ 
ers  have  the  ability  to  copy-protect  their  software  and 
choose  not  to.  Their  words  say  it’s  a  big  problem;  their 
actions  say  it  is  not.  And  if  they  don 't  care,  I  don 't  care. 
With  [Windows]  XP  activation,  Microsoft  is  now  saying 
that  it  cares,  as  is  its  right.  Microsoft  is  also  saying  take 
it  or  leave  it,  as  is  its  right.  Perhaps  some  users  will  opt 
for  a  competitor's  product,  which  does  not  require  acti¬ 
vation,  and  Microsoft's  sales  will  suffer.That  is  all  Micro¬ 
soft’s  risk  to  take,  as  it  sees  fit.  They  don ’t  need  my  help 
in  figuring  out  how  to  make  money. ” 

—  e-mail  from  “one  reader” 


of  dongles 

Wow!  Did  I  open  up  a  can  of  worms  or  what  with 
my  column  suggesting  that  dongles  might  be  a  bet¬ 
ter  antipiracy  mechanism  than  the  likes  of  Micro¬ 
soft’s  Product  Activation  system?  For  those  of  you 
who  missed  it,  check  out  “Let’s  do  IT  with  a  dongle” 
(www.nwfusion.com,  DocFinder:  7942). 

1  haven’t  had  a  chance  to  count  the  yeas  and  nays, 
but  it  appears  that  it  is  roughly  a  50-50  split  on  the 
fundamental  question  of  to  dongle  or  not  to  dongle. 

In  the  barrage  of  mail, some  interesting  themes 
emerged  . . .  that  is,  themes  other  than  “you  are  a  run¬ 
ning  dog  of  capitalism”  and  “rot  in  hell,  heretic.” 

A  major  theme  was  dongles  won’t  work.  One  read¬ 
er  wrote  with  the  weight  of  experience:“As  a  user  of 
dongles  in  the  past,  I  know  that  someone  has  to 
manage  them,  create  them,  correspond  a  particular 
dongle  to  a  particular  software  instance  and  provide 
customer  support  for  lost  or  damaged  dongles.” 

I  absolutely  agree,  the  old  dongle  technologies 
were  neither  reliable  nor  particularly  practical.  But  I 
wasn’t  suggesting  a  return  to  what  we  used  to  use,  1 
was  suggesting  that  we  need  new  standards  and 
technologies  to  make  dongles  practical.  (Oh,  and 
by  the  way,  thanks  to  all  who  corrected  me  on 
Autocad’s  use  of  dongles  —  they  gave  it  up  some 
time  ago.) 

Several  readers  who  seemed  in  favor  of  donglism 
suggested  that  a  smartcard  technology  would  make 


sense,  particularly  if  multiple  access  codes  could 
be  merged  onto  a  single  card. 

But  where  things  got  really  interesting  was  in 
the  thoughts  concerning  piracy  and  how  to  pre¬ 
vent  it.  One  reader  had  this  to  say: “Your  closing 
comment  refers  to  the  requirement  of  a  rational, 
ethical  user  group.  If  the  bulk  of  the  users  were 
rational  and  ethical  then  what  would  be  the  point 
of  the  dongle?  To  punish  the  majority  for  the  sins 
of  the  few?” 

This  misses  the  point. The  software  vendors  aren’t 
trying  to  “punish”  anyone. They  are  trying  to  pre¬ 
vent  misappropriation  of  their  intellectual  property. 
And  the  requirement  for  rational  and  ethical  users 
was  to  support  the  adoption  of  an  effective  soft¬ 
ware  protection  system,  not  to  underpin  the  sys¬ 
tem’s  functioning. 

Basically,  if  more  of  us  said  that  we  understood 
the  need  for  software  protection,  that  we  would 
accept  its  use  and  we  would  collaborate  on  the 
underlying  technology  and  market  framework,  the 
goal  of  significantly  minimizing  piracy  could  and 
would  be  realized. 

Darn,  I’ve  run  out  of  space  before  I  could  tackle 
the  biggest  issue  of  the  lot  so,  next  week,  the  ethics 
of  making  software  and  furniture. 

Dongle  dangling  to  nwcolumn@gibbs.com. 
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Taking  security  to  the  next  level 

Back  at  the  daily  newspaper  where  Buzz  worked 
before  joining  Network  World,  there  was  a  particular¬ 
ly  painful  lesson  we  learned  the  hard  way:  Readers 
forgive  few  sins  more  grudgingly  than  a  misprint  of 
the  winning  lottery  number. 

Imagine  thinking  you'd  won  a  bundle,  only  to  learn 
that  the  paper  screwed  up.  Worse  yet,  imagine 
tossing  a  winning  ticket  in  the  trash. 

Or  imagine  you  were  in  charge  of  Web  site  security  for  the  Texas  lottery,  which 
was  recently  defaced  by  hackers.  Think  you’d  want  to  check  those  winning  numbers 
right  away  to  make  sure  no  one  messed  with  them? 

There  was  no  serious  damage  this  time,  but  executives  at  KaVaDo,  a  New  York 
start-up,  use  the  recent  Texas  episode  in  pitching  their  message  that  comprehensive 
network  security  requires  attention  at  the  application  layer. 

"You  don’t  need  to  be  technically  savvy  to  hack  an  application,"  saysTal  Gilat,  co¬ 
founder  and  CEO. 

Gilat  drives  the  point  home  in  a  demonstration  of  how  easy  it  can  be  to  compro¬ 
mise  a  poorly  conceived  username-and-password  system.  He  says  they  pulled  the 
same  trick  while  making  a  sales  presentation  to  bank  executives  —  on  the  bank's 
Web  site  — -  and  watched  as  "their  faces  went  white." 

KaVaDo’s  products  —  a  vulnerability  assessment  tool  called  ScanDo  and  an  intru¬ 
sion-blocking  system  called  InterDo  —  provide  an  extra  layer  of  expense  in  addition 
to  added  protection,  but  Gilat  says  he's  gotten  little  push-back  on  the  $15,000  prices. 

He  got  none  from  those  bankers. 

It’s  My  Party'  and  I'll  cry  if  I  want  to 

'Chicken  Little"  may  be  the  patron  saint  of  antivirus  software  vendors,  but  that 
didn’t  stop  Buzz  from  taking  a  quick  peek  skyward  after  reading  about  the  "My 


Party"  virus  circulating  last  week. 

Who  wouldn’t  be  unnerved  by  a  virus  that  masquerades  as  a  simple  URL? 

And  shortly  after  reading  about  "My  Party,"  what  pops  into  my  mailbox  but  a 
missive  from  Network  World's  crackerjack  help  desk  with  the  subject  line:  "Virus 
Alert  —  new  photos  from  my  party!” ...  It  included  a  URL  that  promised  me 
more  information  about  the  threat. 

Hmm,  to  click  or  not  to  click,  that  was  the  question. 

This  time  the  e-mail  really  was  from  our  help  desk.  What  if  next  time  it  isn't?  . . . 
Have  you  glanced  outside  yet? 

Getting  the  rank-and-file  to  resist  temptation  and  avoid  opening  executable 
attachments  has  proven  daunting  enough. 

Training  users  to  avoid  infected  URLs  might  be  harder  than  teaching  them 
Chinese. 

Spam  by  any  other  name . . . 

Mobile  phone  users  really  don't  mind  receiving  text  advertisements  via  Short 
Message  Service,  according  to  a  survey  commissioned  by  those  impartial  social 
scientists  at  the  Nokia  mobile  phone  company. 

A  press  release  about  the  survey  claims  that  86%  of  3,300  phone  users  polled  in 
11  countries  "said  they  would  accept  'some  advertising’  if  it  helped  keep  the  cost 
of  mobile  services  down.” 

Well,  at  the  risk  of  sounding  Clintonian,  doesn't  the  question  ultimately  depend 
on  the  definition  of  “some"? 

If  we’re  talking  one  or  two  advertising  messages  a  day  in  return  for  a  25%  dis¬ 
count,  then  where  do  we  sign  up? 

But,  if  we’re  talking  about  anything  like  the  levels  of  spam  flooding  my  various 
in-boxes  —  in  exchange  for  a  nebulous  promise  of  lower  service  fees  —  then  that 
86%  figure  means  less  than  a  carefully  parsed  presidential  denial. 

Spam  by  any  other  name  still  smells  like  low  tide. 

The  address  is  buzz@nww.com.  No  soliciting. 
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A  box  that  delivers  paper  documents  anywhere  overnight? 
Or  a  box  that  delivers  them  instantly  over  the  internet? 


The  Canon  imageRUNNER  with  document  distribution  technology. 

You  can  send  paper  documents  anywhere,  in  any  form,  at  anytime,  right  over  your  network  or  the  internet. 
Instantaneously.  Simply  scan  a  document  into  the  imageRUNNER  5000,  and  you  can  send  it  to  any  desktop, 
e-mail  address,  fax  machine,  database  or  file  server.  And  since  the  Canon  imageRUNNER  is  capable  of 
integrating  directly  with  your  existing  e-mail,  lanfax,  and  document  management  software,  you  can 
maximize  your  investment  in  these  systems*.  The  cost  and  hassle  of  overnight  delivery  are  finally  over. 
At  Canon,  we’re  giving  people  the  know-how  to  make  paper  documents  work  in  an  internet  world. 
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Call  1-866-25-CANON  or  visit  www.imagerunner.com 
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NetVanta*  2000 
Series:  VPN/Internet 
Security  Solutions 

Secure  communication 
over  Internet  and  IP  M 
networks  M 

Standards-based 
VPN  gateways  with 
integrated  firewall 

Stateful  inspection 
firewall  protects  against 
cyber  attacks 

Internal  router 
supports  multiple  users 

Network  Address 
Translation  (NAT)  conceals 
private  IP  addresses 

Data  Encryption 
Standard  (DES)  or3DES 
secures  data 

Internet  Key  Exchange 
(IKE)  authenticates  users 

Web-based  configuration 
and  management 

Reliable  pre-  and 
post-sales  support 

Reassuring  five-year  warranty 
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Secure  VPN  solutions  front 
the  leader  in  WAN  connectivity. 


The  Manta'  2000  Series  from  ADTRAN' 


In  choosing  your  VPN  access  solution,  consider  the 
company  that  makes  connectivity  its  business.  The 

NetVanta'':  2000  VPN /Internet  Security  series  comes  to  you 
from  ADTRAN1' — a  company  that  sells  more  enterprise 
networking  equipment  across  more  service  technologies  than 
any  other  vendor.  A  company  with  more  than  250  established 
products  for  fast,  reliable  and  economical  connectivity. 


The  NetVanta  2000  series  is  a  logical  extension  of 
ADTRAN’s  dynamic  networking  line,  and  is  one  of  the  most 
risk-free  decisions  you  can  make  for  VPN.  It  carries  the 
ADTRAN  reputation  for  quality,  reliability  and 
dependability.  A  reputation  evidenced  by 
leading  market  share  positions  year  after  year. 

Whether  you’re  a  small,  medium,  or  large 
business,  the  NetVanta  2000  series  delivers  the 
exact  VPN  functionality  you’re  seeking,  backed  by 
a  five-year  warranty  and  great  technical  support. 
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Host  Site  Office 

NetVanta  2300 


Small  Office/Homi 

NetVanta  21 


Mobile  User 

NetVanta  VPN  Client 


ADfRAN.  Ask  for  it  by  name. 


For  a  free  VPN  technology  primer,  visit 
www.adtran.com/n  vv0 1 2802 


877.894.4614  Technical  Questions 
877.280.8416  Where  to  Buy 


Experts  choose  AOTRANT 


Adirati 


See  us  at  Comnet 
Booth  #416 


